Computer Security
[EN] securityvulns.ru
no-pyccku



Multiple bugs in Shambala Server
updated since 10.10.2000
Published:01.06.2002
Source:BUGTRAQ
SecurityVulns ID:605
Type:remote
Level:5/10
Description:DoS, directory traversal.
Affected:EVOLVABLE : Shambala Server 4.5
Original documentdocumentDaniel Nyström, [[ TH 026 Inc. ]] SA #3 - Shambala Server 4.5, Directory Traversal and DoS (01.06.2002)
 documentzillion, Shambala 4.5 vulnerability (10.10.2000)
Files:PoC exploit for the DoS in Shambala Server 4.5
Discuss:Read or add your comments to this news (0 comments)

Multiple buffer overflows in mnews
Published:01.06.2002
Source:BUGTRAQ
SecurityVulns ID:2062
Type:client
Level:5/10
Description:Buffer overflows on command line processing, environment variables and NNTP server response handling.
Affected:mnews : mnews 1.22
Original documentdocumentzillion, SRT Security Advisory (SRT2002-04-31-1159): Mnews (01.06.2002)
Files:Remote FreeBSD exploit for the Mnews port version 1.22
Discuss:Read or add your comments to this news (0 comments)

File system access in imap-uw
Published:01.06.2002
Source:3APA3A
SecurityVulns ID:2063
Type:remote
Level:5/10
Description:By design it's possible to access any file readable by user's account.
Affected:UW : imap-uw 2001
Original documentdocument3APA3A, SECURITY.NNOV: Courier CPU exhaustion + bonus on imap-uw (01.06.2002)
Files:imap-uw remote file access utilities
Discuss:Read or add your comments to this news (0 comments)

Multiple bugs in QNX
updated since 01.06.2002
Published:13.06.2002
Source:BUGTRAQ
SecurityVulns ID:2061
Type:local
Level:7/10
Description:User can create the hard link for a file not owned by him. ptrace() can be attached to suid process, signals may be passed to any process, buffer overflows and privelege escalations in many utilities.
Affected:QNX : QNX 4.25
Original documentdocumentEgor Egorov, madcr: QnX 4.25 - multiples bof in suid/no suid files (13.06.2002)
 documentbadc0ded_(at)_badc0ded.com, QNX (04.06.2002)
 documentSimon Ouellette, Multiple vulnerabilities in QNX (01.06.2002)
Discuss:Read or add your comments to this news (0 comments)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
 



Рейтинг@Mail.ru