Computer Security
[EN] securityvulns.ru no-pyccku


ZyXel wireless routers DoS
Published:20.03.2007
Source:
SecurityVulns ID:7436
Type:remote
Threat Level:
5/10
Affected:ZYXEL : ZynOS 3.40
CVE:CVE-2007-1586 (ZynOS 3.40 allows remote attackers to cause a denial of service (link restart) by sending a request for the name \M via the SMB Mail Slot Protocol.)
Original documentdocumentJose Antonio, ZynOS v3.40 One packet killer (20.03.2007)

OpenAFS filesystem privilege esccalation
Published:20.03.2007
Source:
SecurityVulns ID:7438
Type:local
Threat Level:
5/10
Description:Attacke can make fake suid binary on network disk by using protocol weakness.
Affected:OPENAFS : OpenAFS 1.3
CVE:CVE-2007-1507 (The default configuration in OpenAFS 1.4.x before 1.4.4 and 1.5.x before 1.5.17 supports setuid programs within the local cell, which might allow attackers to gain privileges by spoofing a response to an AFS cache manager FetchStatus request, and setting setuid and root ownership for files in the cache.)
Original documentdocumentDEBIAN, [SECURITY] [DSA 1271-1] New openafs packages fix remote privilege escalation bug (20.03.2007)

Cisco 7940 IP Phone denial of service
updated since 20.03.2007
Published:21.03.2007
Source:
SecurityVulns ID:7437
Type:remote
Threat Level:
5/10
Description:Crash on malformed INVITE SIP packet.
Affected:CISCO : Cisco 7940
 CISCO : Cisco 7960
CVE:CVE-2007-1542 (Unspecified vulnerability in the Cisco IP Phone 7940 and 7960 running firmware before POS8-6-0 allows remote attackers to cause a denial of service via the Remote-Party-ID sipURI field in a SIP INVITE request. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.)
Original documentdocumentCISCO, Re: [Full-disclosure] CISCO Phone 7940 DOS vulnerability (21.03.2007)
 documentRadu State, [Full-disclosure] CISCO Phone 7940 DOS vulnerability (20.03.2007)

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod