Monthly Archive: September 1999

CVE-1999-0048

Talkd, when given corrupt DNS information, can be used to execute arbitrary commands with root privileges. Date published : 1999-09-29

CVE-1999-0046

Buffer overflow of rlogin program using TERM environmental variable. Date published : 1999-09-29

CVE-1999-0045

List of arbitrary files on Web host via nph-test-cgi script. Date published : 1999-09-29

CVE-1999-0043

Command execution via shell metachars in INN daemon (innd) 1.5 using "newgroup" and "rmgroup" control messages, and others. Date published : 1999-09-29

CVE-1999-0042

Buffer overflow in University of Washington’s implementation of IMAP and POP servers. Date published : 1999-09-29

CVE-1999-0041

Buffer overflow in NLS (Natural Language Service). Date published : 1999-09-29

CVE-1999-0040

Buffer overflow in Xt library of X Windowing System allows local users to execute commands with root privileges. Date published : 1999-09-29

CVE-1999-0039

webdist CGI program (webdist.cgi) in SGI IRIX allows remote attackers to execute arbitrary commands via shell metacharacters in the distloc parameter. Date published : 1999-09-29 http://www.securityfocus.com/bid/374

CVE-1999-0038

Buffer overflow in xlock program allows local users to execute commands as root. Date published : 1999-09-29

CVE-1999-0037

Arbitrary command execution via metamail package using message headers, when user processes attacker’s message using metamail. Date published : 1999-09-29

CVE-1999-0036

IRIX login program with a nonzero LOCKOUT parameter allows creation or damage to files. Date published : 1999-09-29

CVE-1999-0035

Race condition in signal handling routine in ftpd, allowing read/write arbitrary files. Date published : 1999-09-29