Monthly Archive: September 1999

CVE-1999-0097

The AIX FTP client can be forced to execute commands from a malicious server through shell metacharacters (e.g. a pipe character). Date published : 1999-09-29

CVE-1999-0096

Sendmail decode alias can be used to overwrite sensitive files. Date published : 1999-09-29

CVE-1999-0094

AIX piodmgrsu command allows local users to gain additional group privileges. Date published : 1999-09-29

CVE-1999-0093

AIX nslookup command allows local users to obtain root access by not dropping privileges correctly. Date published : 1999-09-29

CVE-1999-0091

Buffer overflow in AIX writesrv command allows local users to obtain root access. Date published : 1999-09-29

CVE-1999-0090

Buffer overflow in AIX rcp command allows local users to obtain root access. Date published : 1999-09-29

CVE-1999-0087

Denial of service in AIX telnet can freeze a system and prevent users from accessing the server. Date published : 1999-09-29 http://www.osvdb.org/7992

CVE-1999-0083

getcwd() file descriptor leak in FTP. Date published : 1999-09-29

CVE-1999-0081

wu-ftp allows files to be overwritten via the rnfr command. Date published : 1999-09-29

CVE-1999-0080

Certain configurations of wu-ftp FTP server 2.4 use a _PATH_EXECPATH setting to a directory with dangerous commands, such as /bin, which allows remote authenticated users to gain root access via the "site exec" command....