<?xml version="1.0"?>
<cve xmlns="http://cve.mitre.org/cve/downloads/xml_schema_info.html" xmlns:cve="http://cve.mitre.org/cve/downloads/xml_schema_info.html" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://cve.mitre.org/cve/downloads/xml_schema_info.html cve_schema.xsd" schemaVersion="0.1">
<item type="CAN" name="CVE-1999-0001" seq="1999-0001">
<status>Candidate</status>
<phase date="20051217">Modified</phase>
<desc>ip_input.c in BSD-derived TCP/IP implementations allows remote attackers to cause a denial of service (crash or hang) via crafted packets.</desc>
<refs>
<ref source="CERT">CA-98-13-tcp-denial-of-service</ref>
<ref source="BUGTRAQ">19981223 Re: CERT Advisory CA-98.13 - TCP/IP Denial of Service</ref>
<ref source="CONFIRM" url="http://www.openbsd.org/errata23.html#tcpfix">http://www.openbsd.org/errata23.html#tcpfix</ref>
<ref source="OSVDB" url="http://www.osvdb.org/5707">5707</ref>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="2">Northcutt, Wall</noop>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Christey">A Bugtraq posting indicates that the bug has to do with
&quot;short packets with certain options set,&quot; so the description
should be modified accordingly.

But is this the same as CVE-1999-0052?  That one is related
to nestea (CVE-1999-0257) and probably the one described in
BUGTRAQ:19981023 nestea v2 against freebsd 3.0-Release
The patch for nestea is in ip_input.c around line 750.
The patches for CVE-1999-0001 are in lines 388&amp;446.  So, 
CVE-1999-0001 is different from CVE-1999-0257 and CVE-1999-0052.
The FreeBSD patch for CVE-1999-0052 is in line 750.
So, CVE-1999-0257 and CVE-1999-0052 may be the same, though
CVE-1999-0052 should be RECAST since this bug affects Linux
and other OSes besides FreeBSD.</comment>
<comment voter="Frech">XF:teardrop(338)
This assignment was based solely on references to the CERT advisory.</comment>
<comment voter="Christey">The description for BID:190, which links to CVE-1999-0052 (a
FreeBSD advisory), notes that the patches provided by FreeBSD in
CERT:CA-1998-13 suggest a connection between CVE-1999-0001 and
CVE-1999-0052.  CERT:CA-1998-13 is too vague to be sure without
further analysis.</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0002" seq="1999-0002">
<status>Entry</status>
<desc>Buffer overflow in NFS mountd gives root access to remote attackers, mostly in Linux systems.</desc>
<refs>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19981006-01-I">19981006-01-I</ref>
<ref source="CERT">CA-98.12.mountd</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-006.shtml">J-006</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/121">121</ref>
<ref source="XF">linux-mountd-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0003" seq="1999-0003">
<status>Entry</status>
<desc>Execute commands as root via buffer overflow in Tooltalk database server (rpc.ttdbserverd).</desc>
<refs>
<ref source="NAI">NAI-29</ref>
<ref source="CERT">CA-98.11.tooltalk</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19981101-01-A">19981101-01-A</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19981101-01-PX">19981101-01-PX</ref>
<ref source="XF">aix-ttdbserver</ref>
<ref source="XF">tooltalk</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/122">122</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0004" seq="1999-0004">
<status>Candidate</status>
<phase date="19990621">Modified</phase>
<desc>MIME buffer overflow in email clients, e.g. Solaris mailtool and Outlook.</desc>
<refs>
<ref source="CERT">CA-98.10.mime_buffer_overflows</ref>
<ref source="XF">outlook-long-name</ref>
<ref source="SUN">00175</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms98-008.asp">MS98-008</ref>
</refs>
<votes>
<accept count="8">Magdych, Northcutt, Wall, Baker, Landfield, Cole, Dik, Collins</accept>
<modify count="1">Frech</modify>
<noop count="1">Christey</noop>
<reviewing count="1">Shostack</reviewing>
</votes>
<comments>
<comment voter="Frech">Extremely minor, but I believe e-mail is the correct term. (If you reject
this suggestion, I will not be devastated.) :-)</comment>
<comment voter="Christey">This issue seems to have been rediscovered in
BUGTRAQ:20000515 Eudora Pro &amp; Outlook Overflow - too long filenames again
http://marc.theaimsgroup.com/?l=bugtraq&amp;m=95842482413076&amp;w=2

Also see
BUGTRAQ:19990320 Eudora Attachment Buffer Overflow
http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92195396912110&amp;w=2</comment>
<comment voter="Christey"> 
CVE-2000-0415 may be a later rediscovery of this problem
for Outlook.</comment>
<comment voter="Dik">Sun bug 4163471,</comment>
<comment voter="Christey">ADDREF BID:125</comment>
<comment voter="Christey">BUGTRAQ:19980730 Long Filenames &amp; Lotus Products
URL:http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221104526201&amp;w=2</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0005" seq="1999-0005">
<status>Entry</status>
<desc>Arbitrary command execution via IMAP buffer overflow in authenticate command.</desc>
<refs>
<ref source="CERT">CA-98.09.imapd</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/177">00177</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/130">130</ref>
<ref source="XF">imap-authenticate-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0006" seq="1999-0006">
<status>Entry</status>
<desc>Buffer overflow in POP servers based on BSD/Qualcomm's qpopper allows remote attackers to gain root access using a long PASS command.</desc>
<refs>
<ref source="CERT">CA-98.08.qpopper_vul</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980801-01-I">19980801-01-I</ref>
<ref source="AUSCERT">AA-98.01</ref>
<ref source="XF">qpopper-pass-overflow</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/133">133</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0007" seq="1999-0007">
<status>Entry</status>
<desc>Information from SSL-encrypted sessions via PKCS #1.</desc>
<refs>
<ref source="CERT">CA-98.07.PKCS</ref>
<ref source="MS" url="http://www.microsoft.com/technet/security/bulletin/ms98-002.mspx">MS98-002</ref>
<ref source="XF">nt-ssl-fix</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0008" seq="1999-0008">
<status>Entry</status>
<desc>Buffer overflow in NIS+, in Sun's rpc.nisd program.</desc>
<refs>
<ref source="CERT">CA-98.06.nisd</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/170">00170</ref>
<ref source="ISS">June10,1998</ref>
<ref source="XF">nisd-bo-check</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0009" seq="1999-0009">
<status>Entry</status>
<desc>Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases.</desc>
<refs>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980603-01-PX">19980603-01-PX</ref>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9808-083">HPSBUX9808-083</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/180">00180</ref>
<ref source="CERT">CA-98.05.bind_problems</ref>
<ref source="XF">bind-bo</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/134">134</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0010" seq="1999-0010">
<status>Entry</status>
<desc>Denial of Service vulnerability in BIND 8 Releases via maliciously formatted DNS messages.</desc>
<refs>
<ref source="CERT">CA-98.05.bind_problems</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980603-01-PX">19980603-01-PX</ref>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9808-083">HPSBUX9808-083</ref>
<ref source="XF">bind-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0011" seq="1999-0011">
<status>Entry</status>
<desc>Denial of Service vulnerabilities in BIND 4.9 and BIND 8 Releases via CNAME record and zone transfer.</desc>
<refs>
<ref source="CERT">CA-98.05.bind_problems</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980603-01-PX">19980603-01-PX</ref>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9808-083">HPSBUX9808-083</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/180">00180</ref>
<ref source="XF">bind-axfr-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0012" seq="1999-0012">
<status>Entry</status>
<desc>Some web servers under Microsoft Windows allow remote attackers to bypass access restrictions for files with long file names.</desc>
<refs>
<ref source="CERT">CA-98.04.Win32.WebServers</ref>
<ref source="XF">nt-web8.3</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0013" seq="1999-0013">
<status>Entry</status>
<desc>Stolen credentials from SSH clients via ssh-agent program, allowing other local users to access remote accounts belonging to the ssh-agent user.</desc>
<refs>
<ref source="CERT">CA-98.03.ssh-agent</ref>
<ref source="NAI">NAI-24</ref>
<ref source="XF">ssh-agent</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0014" seq="1999-0014">
<status>Entry</status>
<desc>Unauthorized privileged access or denial of service via dtappgather program in CDE.</desc>
<refs>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9801-075">HPSBUX9801-075</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/185">00185</ref>
<ref source="CERT">CA-98.02.CDE</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0015" seq="1999-0015">
<status>Candidate</status>
<phase date="19990726">Proposed</phase>
<desc>Teardrop IP denial of service.</desc>
<refs>
<ref source="CERT">CA-97.28.Teardrop_Land</ref>
<ref source="XF">teardrop</ref>
</refs>
<votes>
<accept count="1">Wall</accept>
<modify count="1">Frech</modify>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Frech">XF: teardrop-mod</comment>
<comment voter="Christey">Not sure how many separate &quot;instances&quot; of Teardrop there are.
See: CVE-1999-0015, CVE-1999-0104, CVE-1999-0257, CVE-1999-0258</comment>
<comment voter="Christey">See the SCO advisory at:
http://www.securityfocus.com/templates/advisory.html?id=1411
which may further clarify the issue.</comment>
<comment voter="Christey">MSKB:Q154174
MSKB:Q154174 (CVE-1999-0015) and MSKB:Q179129 (CVE-1999-0104)
indicate that CVE-1999-0015 was fixed in NT SP3, but
CVE-1999-0104 was not.  Thus CD:SF-LOC suggests that the
problems keep separate candidates because one problem appears
in a different version than the other.</comment>
<comment voter="Christey">BID:124
http://www.securityfocus.com/bid/124
Consider MSKB:Q154174
http://support.microsoft.com/support/kb/articles/q154/1/74.asp
Consider BUGTRAQ:19971113 Linux IP fragment overlap bug
http://www.securityfocus.com/archive/1/8014</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0016" seq="1999-0016">
<status>Entry</status>
<desc>Land IP denial of service.</desc>
<refs>
<ref source="CERT">CA-97.28.Teardrop_Land</ref>
<ref source="FREEBSD">FreeBSD-SA-98:01</ref>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9801-076">HPSBUX9801-076</ref>
<ref source="CISCO">http://www.cisco.com/warp/public/770/land-pub.shtml</ref>
<ref source="XF">cisco-land</ref>
<ref source="XF">land</ref>
<ref source="XF">95-verv-tcp</ref>
<ref source="XF">land-patch</ref>
<ref source="XF">ver-tcpip-sys</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0017" seq="1999-0017">
<status>Entry</status>
<desc>FTP servers can allow an attacker to connect to arbitrary ports on machines other than the FTP client, aka FTP bounce.</desc>
<refs>
<ref source="CERT">CA-97.27.FTP_bounce</ref>
<ref source="XF">ftp-bounce</ref>
<ref source="XF">ftp-privileged-port</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0018" seq="1999-0018">
<status>Entry</status>
<desc>Buffer overflow in statd allows root privileges.</desc>
<refs>
<ref source="CERT">CA-97.26.statd</ref>
<ref source="AUSCERT">AA-97.29</ref>
<ref source="XF">statd</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/127">127</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0019" seq="1999-0019">
<status>Entry</status>
<desc>Delete or create a file via rpc.statd, due to invalid information.</desc>
<refs>
<ref source="CERT">CA-96.09.rpc.statd</ref>
<ref source="XF">rpc-stat</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/135">00135</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0020" seq="1999-0020">
<status>Candidate</status>
<phase date="20050204">Modified</phase>
<desc>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-1999-0032.  Reason: This candidate is a duplicate of CVE-1999-0032.  Notes: All CVE users should reference CVE-1999-0032 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</desc>
<refs>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="4">Levy, Northcutt, Wall, Shostack</noop>
<reject count="2">Christey, Baker</reject>
</votes>
<comments>
<comment voter="Frech">XF:lpr-bo</comment>
<comment voter="Christey">DUPE CVE-1999-0032, which includes XF:lpr-bo</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0021" seq="1999-0021">
<status>Entry</status>
<desc>Arbitrary command execution via buffer overflow in Count.cgi (wwwcount) cgi-bin program.</desc>
<refs>
<ref source="BUGTRAQ">19971010 Security flaw in Count.cgi (wwwcount)</ref>
<ref source="CERT">CA-97.24.Count_cgi</ref>
<ref source="XF">http-cgi-count</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/128">128</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0022" seq="1999-0022">
<status>Entry</status>
<desc>Local user gains root privileges via buffer overflow in rdist, via expstr() function.</desc>
<refs>
<ref source="CERT">CA-97.23.rdist</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/179">00179</ref>
<ref source="XF">rdist-bo3</ref>
<ref source="XF">rdist-sept97</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0023" seq="1999-0023">
<status>Entry</status>
<desc>Local user gains root privileges via buffer overflow in rdist, via lookup() function.</desc>
<refs>
<ref source="CERT">CA-96.14.rdist_vul</ref>
<ref source="XF">rdist-bo</ref>
<ref source="XF">rdist-bo2</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0024" seq="1999-0024">
<status>Entry</status>
<desc>DNS cache poisoning via BIND, by predictable query IDs.</desc>
<refs>
<ref source="CERT">CA-97.22.bind</ref>
<ref source="XF">bind</ref>
<ref source="NAI">NAI-11</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0025" seq="1999-0025">
<status>Entry</status>
<desc>root privileges via buffer overflow in df command on SGI IRIX systems.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1997-21.html">CA-1997-21</ref>
<ref source="AUSCERT">AA-97.19.IRIX.df.buffer.overflow.vul</ref>
<ref source="SGI">SGI:19970505-01-A</ref>
<ref source="SGI">SGI:19970505-02-PX</ref>
<ref source="CERT-VN" url="http://www.kb.cert.org/vuls/id/20851">VU#20851</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/346">346</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/440">df-bo(440)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0026" seq="1999-0026">
<status>Entry</status>
<desc>root privileges via buffer overflow in pset command on SGI IRIX systems.</desc>
<refs>
<ref source="CERT">CA-97.21.sgi_buffer_overflow</ref>
<ref source="AUSCERT">AA-97.20.IRIX.pset.buffer.overflow.vul</ref>
<ref source="XF">pset-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0027" seq="1999-0027">
<status>Entry</status>
<desc>root privileges via buffer overflow in eject command on SGI IRIX systems.</desc>
<refs>
<ref source="CERT">CA-97.21.sgi_buffer_overflow</ref>
<ref source="AUSCERT">AA-97.21.IRIX.eject.buffer.overflow.vul</ref>
<ref source="XF">eject-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0028" seq="1999-0028">
<status>Entry</status>
<desc>root privileges via buffer overflow in login/scheme command on SGI IRIX systems.</desc>
<refs>
<ref source="CERT">CA-97.21.sgi_buffer_overflow</ref>
<ref source="AUSCERT">AA-97.22.IRIX.login.scheme.buffer.overflow.vul</ref>
<ref source="XF">sgi-schemebo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0029" seq="1999-0029">
<status>Entry</status>
<desc>root privileges via buffer overflow in ordist command on SGI IRIX systems.</desc>
<refs>
<ref source="CERT">CA-97.21.sgi_buffer_overflow</ref>
<ref source="AUSCERT">AA-97.23-IRIX.ordist.buffer.overflow.vul</ref>
<ref source="XF">ordist-bo</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0030" seq="1999-0030">
<status>Candidate</status>
<phase date="19990623">Proposed</phase>
<desc>root privileges via buffer overflow in xlock command on SGI IRIX systems.</desc>
<refs>
<ref source="CERT">CA-97.21.sgi_buffer_overflow</ref>
<ref source="AUSCERT">AA-97.24.IRIX.xlock.buffer.overflow.vul</ref>
<ref source="XF">sgi-xlockbo</ref>
<ref source="SGI">19970508-02-PX</ref>
</refs>
<votes>
<accept count="3">Ozancin, Levy, Prosser</accept>
<noop count="1">Baker</noop>
<recast count="1">Frech</recast>
<reject count="1">Christey</reject>
</votes>
<comments>
<comment voter="Frech">XF:xlock-bo (also add)
As per xlock-bo, also appears on AIX, BSDI, DG/UX, FreeBSD, Solaris, and
several Linii.
Also, don't you mean to cite SGI:19970502-02-PX? The one you list is
login/scheme.</comment>
<comment voter="Levy">Notice that this xlock overflow is the same as in
CA-97.13. CA-97.21 simply is a reminder.</comment>
<comment voter="Christey">As pointed out by Elias, CA-97.21 states: &quot;For more
information about vulnerabilities in xlock... see CA-97.13&quot;
CA-97.13 = CVE-1999-0038.
This may also be a duplicate with CVE-1999-0306.

See exploits at:

http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167418394&amp;w=2
http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167418404&amp;w=2

Sun also has this problem, at
http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/150&amp;type=0&amp;nav=sec.sba</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0031" seq="1999-0031">
<status>Entry</status>
<desc>JavaScript in Internet Explorer 3.x and 4.x, and Netscape 2.x, 3.x and 4.x, allows remote attackers to monitor a user's web activities, aka the Bell Labs vulnerability.</desc>
<refs>
<ref source="CERT">CA-97.20.javascript</ref>
<ref source="HP" url="http://www.codetalker.com/advisories/vendor/hp/hpsbux9707-065.html">HPSBUX9707-065</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0032" seq="1999-0032">
<status>Entry</status>
<desc>Buffer overflow in lpr, as used in BSD-based systems including Linux, allows local users to execute arbitrary code as root via a long -C (classification) command line option.</desc>
<refs>
<ref source="BUGTRAQ">19960813 Possible bufferoverflow condition in lpr, xterm and xload</ref>
<ref source="BUGTRAQ">19961025 Linux &amp; BSD's lpr exploit</ref>
<ref source="MLIST">[freebsd-security] 19961025 Vadim Kolontsov: BoS: Linux &amp; BSD's lpr exploit</ref>
<ref source="MLIST">[linux-security] 19961122 LSF Update#14: Vulnerability of the lpr program.</ref>
<ref source="CERT">CA-97.19.bsdlp</ref>
<ref source="AUSCERT">AA-96.12</ref>
<ref source="CIAC">H-08</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/i-042.shtml">I-042</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980402-01-PX">19980402-01-PX</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/707">707</ref>
<ref source="XF">bsd-lprbo2</ref>
<ref source="XF">bsd-lprbo</ref>
<ref source="XF">lpr-bo</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0033" seq="1999-0033">
<status>Candidate</status>
<phase date="20040811">Modified</phase>
<desc>Command execution in Sun systems via buffer overflow in the at program.</desc>
<refs>
<ref source="CERT">CA-97.18.at</ref>
<ref source="SUN">00160</ref>
<ref source="XF">sun-atbo</ref>
</refs>
<votes>
<accept count="8">Hill, Northcutt, Wall, Baker, Cole, Dik, Shostack, Collins</accept>
<noop count="1">Christey</noop>
<recast count="1">Frech</recast>
</votes>
<comments>
<comment voter="Frech">This vulnerability also manifests itself for the following 
platforms: AIX, HPUX, IRIX, Solaris, SCO, NCR MP-RAS. In this light,
please add the following:
Reference: XF:at-bo</comment>
<comment voter="Dik">Sun bug 1265200, 4063161</comment>
<comment voter="Christey">ADDREF SGI:19971102-01-PX
ftp://patches.sgi.com/support/free/security/advisories/19971102-01-PX
SCO:SB.97:01
ftp://ftp.sco.com/SSE/security_bulletins/SB.97:01a</comment>
<comment voter="Christey">CIAC:F-15
http://ciac.llnl.gov/ciac/bulletins/f-15.shtml
HP:HPSBUX9502-023</comment>
<comment voter="Christey">Add period to the end of the description.</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0034" seq="1999-0034">
<status>Entry</status>
<desc>Buffer overflow in suidperl (sperl), Perl 4.x and 5.x.</desc>
<refs>
<ref source="CERT">CA-97.17.sperl</ref>
<ref source="XF">perl-suid</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0035" seq="1999-0035">
<status>Entry</status>
<desc>Race condition in signal handling routine in ftpd, allowing read/write arbitrary files.</desc>
<refs>
<ref source="XF">ftp-ftpd</ref>
<ref source="CERT">CA-97.16.ftpd</ref>
<ref source="AUSCERT">AA-97.03</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0036" seq="1999-0036">
<status>Entry</status>
<desc>IRIX login program with a nonzero LOCKOUT parameter allows creation or damage to files.</desc>
<refs>
<ref source="CERT">CA-97.15.sgi_login</ref>
<ref source="AUSCERT">AA-97.12</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/h-106.shtml">H-106</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19970508-02-PX">19970508-02-PX</ref>
<ref source="OSVDB" url="http://www.osvdb.org/990">990</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/557">sgi-lockout(557)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0037" seq="1999-0037">
<status>Entry</status>
<desc>Arbitrary command execution via metamail package using message headers, when user processes attacker's message using metamail.</desc>
<refs>
<ref source="CERT">CA-97.14.metamail</ref>
<ref source="XF">metamail-header-commands</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0038" seq="1999-0038">
<status>Entry</status>
<desc>Buffer overflow in xlock program allows local users to execute commands as root.</desc>
<refs>
<ref source="CERT">CA-97.13.xlock</ref>
<ref source="XF">xlock-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0039" seq="1999-0039">
<status>Entry</status>
<desc>webdist CGI program (webdist.cgi) in SGI IRIX allows remote attackers to execute arbitrary commands via shell metacharacters in the distloc parameter.</desc>
<refs>
<ref source="BUGTRAQ">19970507 Re: SGI Security Advisory 19970501-01-A - Vulnerability in</ref>
<ref source="BUGTRAQ">19970507 Re: SGI Advisory: webdist.cgi</ref>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1997-12.html">CA-1997-12</ref>
<ref source="AUSCERT">AA-97.14</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19970501-02-PX">19970501-02-PX</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/374">374</ref>
<ref source="OSVDB" url="http://www.osvdb.org/235">235</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/333">http-sgi-webdist(333)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0040" seq="1999-0040">
<status>Entry</status>
<desc>Buffer overflow in Xt library of X Windowing System allows local users to execute commands with root privileges.</desc>
<refs>
<ref source="CERT">CA-97.11.libXt</ref>
<ref source="XF">libXt-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0041" seq="1999-0041">
<status>Entry</status>
<desc>Buffer overflow in NLS (Natural Language Service).</desc>
<refs>
<ref source="CERT">CA-97.10.nls</ref>
<ref source="XF">nls-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0042" seq="1999-0042">
<status>Entry</status>
<desc>Buffer overflow in University of Washington's implementation of IMAP and POP servers.</desc>
<refs>
<ref source="NAI">NAI-21</ref>
<ref source="CERT">CA-97.09.imap_pop</ref>
<ref source="XF">popimap-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0043" seq="1999-0043">
<status>Entry</status>
<desc>Command execution via shell metachars in INN daemon (innd) 1.5 using &quot;newgroup&quot; and &quot;rmgroup&quot; control messages, and others.</desc>
<refs>
<ref source="CERT">CA-97.08.innd</ref>
<ref source="XF">inn-controlmsg</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0044" seq="1999-0044">
<status>Entry</status>
<desc>fsdump command in IRIX allows local users to obtain root access by modifying sensitive files.</desc>
<refs>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19970301-01-P">19970301-01-P</ref>
<ref source="XF">sgi-fsdump</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0045" seq="1999-0045">
<status>Entry</status>
<desc>List of arbitrary files on Web host via nph-test-cgi script.</desc>
<refs>
<ref source="CERT">CA-97.07.nph-test-cgi_script</ref>
<ref source="XF">http-cgi-nph</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0046" seq="1999-0046">
<status>Entry</status>
<desc>Buffer overflow of rlogin program using TERM environmental variable.</desc>
<refs>
<ref source="CERT">CA-97.06.rlogin-term</ref>
<ref source="XF">rlogin-termbo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0047" seq="1999-0047">
<status>Entry</status>
<desc>MIME conversion buffer overflow in sendmail versions 8.8.3 and 8.8.4.</desc>
<refs>
<ref source="CERT">CA-97.05.sendmail</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/685">685</ref>
<ref source="XF">sendmail-mime-bo2</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0048" seq="1999-0048">
<status>Entry</status>
<desc>Talkd, when given corrupt DNS information, can be used to execute arbitrary commands with root privileges.</desc>
<refs>
<ref source="CERT">CA-97.04.talkd</ref>
<ref source="FREEBSD">FreeBSD-SA-96:21</ref>
<ref source="AUSCERT">AA-97.01</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/147">00147</ref>
<ref source="XF">talkd-bo</ref>
<ref source="XF">netkit-talkd</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0049" seq="1999-0049">
<status>Entry</status>
<desc>Csetup under IRIX allows arbitrary file creation or overwriting.</desc>
<refs>
<ref source="XF">sgi-csetup</ref>
<ref source="CERT">CA-97.03.csetup</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0050" seq="1999-0050">
<status>Entry</status>
<desc>Buffer overflow in HP-UX newgrp program.</desc>
<refs>
<ref source="CERT">CA-97.02.hp_newgrp</ref>
<ref source="AUSCERT">AA-96.16.HP-UX.newgrp.Buffer.Overrun.Vulnerability</ref>
<ref source="XF">hp-newgrpbo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0051" seq="1999-0051">
<status>Entry</status>
<desc>Arbitrary file creation and program execution using FLEXlm LicenseManager, from versions 4.0 to 5.0, in IRIX.</desc>
<refs>
<ref source="XF">sgi-licensemanager</ref>
<ref source="CERT">CA-97.01.flex_lm</ref>
<ref source="AUSCERT">AA-96.03</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0052" seq="1999-0052">
<status>Entry</status>
<desc>IP fragmentation denial of service in FreeBSD allows a remote attacker to cause a crash.</desc>
<refs>
<ref source="FREEBSD">FreeBSD-SA-98:08</ref>
<ref source="OSVDB" url="http://www.osvdb.org/908">908</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/1389">freebsd-ip-frag-dos(1389)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0053" seq="1999-0053">
<status>Entry</status>
<desc>TCP RST denial of service in FreeBSD.</desc>
<refs>
<ref source="FREEBSD">FreeBSD-SA-98:07</ref>
<ref source="OSVDB" url="http://www.osvdb.org/6094">6094</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0054" seq="1999-0054">
<status>Entry</status>
<desc>Sun's ftpd daemon can be subjected to a denial of service.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/171">00171</ref>
<ref source="XF">sun-ftpd</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0055" seq="1999-0055">
<status>Entry</status>
<desc>Buffer overflows in Sun libnsl allow root access.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/172">00172</ref>
<ref source="AIXAPAR" url="http://www-1.ibm.com/support/search.wss?rs=0&amp;q=IX80543&amp;apar=only">IX80543</ref>
<ref source="RSI">RSI.0005.05-14-98.SUN.LIBNSL</ref>
<ref source="XF">sun-libnsl</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0056" seq="1999-0056">
<status>Entry</status>
<desc>Buffer overflow in Sun's ping program can give root access to local users.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/174">00174</ref>
<ref source="XF">sun-ping</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0057" seq="1999-0057">
<status>Entry</status>
<desc>Vacation program allows command execution by remote users through a sendmail command.</desc>
<refs>
<ref source="NAI">NAI-19</ref>
<ref source="XF">vacation</ref>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9811-087">HPSBUX9811-087</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0058" seq="1999-0058">
<status>Entry</status>
<desc>Buffer overflow in PHP cgi program, php.cgi allows shell access.</desc>
<refs>
<ref source="NAI">NAI-12</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/712">712</ref>
<ref source="XF">http-cgi-phpbo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0059" seq="1999-0059">
<status>Entry</status>
<desc>IRIX fam service allows an attacker to obtain a list of all files on the server.</desc>
<refs>
<ref source="NAI">NAI-16</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/353">353</ref>
<ref source="OSVDB" url="http://www.osvdb.org/164">164</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/325">irix-fam(325)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0060" seq="1999-0060">
<status>Entry</status>
<desc>Attackers can cause a denial of service in Ascend MAX and Pipeline routers with a malformed packet to the discard port, which is used by the Java Configurator tool.</desc>
<refs>
<ref source="NAI">NAI-26</ref>
<ref source="XF">ascend-config-kill</ref>
<ref source="ASCEND">http://www.ascend.com/2695.html</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0061" seq="1999-0061">
<status>Candidate</status>
<phase date="19990630">Proposed</phase>
<desc>File creation and deletion, and remote execution, in the BSD line printer daemon (lpd).</desc>
<refs>
<ref source="NAI">NAI-20</ref>
<ref source="XF">bsd-lpd</ref>
</refs>
<votes>
<accept count="3">Hill, Northcutt, Frech</accept>
<recast count="1">Baker</recast>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Christey">This should be split into three separate problems based on
the SNI advisory.  But there's newer information to further
complicate things.

What do we do about this one?  in 1997 or so, SNI did an
advisory on this problem.  In early 2000, it was still
discovered to be present in some Linux systems.  So an 
SF-DISCOVERY content decision might say that this is a
long enough time between the two, so this should be recorded
separately.  But they're the same codebase... so if we keep
them in the same entry, how do we make sure that this entry
reflects that some new information has been discovered?

The use of dot notation may help in this regard, to use one
dot for the original problem as discovered in 1997, and
another dot for the resurgence of the problem in 2000.</comment>
<comment voter="Baker">We should merge these.</comment>
<comment voter="Christey">Perhaps this should be NAI-19 instead of NAI-20?
The original Bugtraq post for the SNI advisory suggests SNI-19:
BUGTRAQ:19971002 SNI-19:BSD lpd vulnerability
URL:SNI-19:BSD lpd vulnerability

Also add:
BUGTRAQ:19971021 SNI-19: BSD lpd vulnerabilities (UPDATE)
URL:http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87747479514310&amp;w=2

However, archives of &quot;NAI-0020&quot; point to the lpd vuln.

If I recall correctly, some of the NAI advisory numbers got
switched when NAI acquired SNI.</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0062" seq="1999-0062">
<status>Entry</status>
<desc>The chpass command in OpenBSD allows a local user to gain root access through file descriptor leakage.</desc>
<refs>
<ref source="XF">openbsd-chpass</ref>
<ref source="NAI">NAI-28</ref>
<ref source="OSVDB" url="http://www.osvdb.org/7559">7559</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0063" seq="1999-0063">
<status>Entry</status>
<desc>Cisco IOS 12.0 and other versions can be crashed by malicious UDP packets to the syslog port.</desc>
<refs>
<ref source="AUSCERT">ESB-98.197</ref>
<ref source="CISCO">http://www.cisco.com/warp/public/770/iossyslog-pub.shtml</ref>
<ref source="XF">cisco-syslog-crash</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0064" seq="1999-0064">
<status>Entry</status>
<desc>Buffer overflow in AIX lquerylv program gives root access to local users.</desc>
<refs>
<ref source="BUGTRAQ">May28,1997</ref>
<ref source="XF">lquerylv-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0065" seq="1999-0065">
<status>Entry</status>
<desc>Multiple buffer overflows in how dtmail handles attachments allows a remote attacker to execute commands.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/181">00181</ref>
<ref source="XF">hp-dtmail</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0066" seq="1999-0066">
<status>Entry</status>
<desc>AnyForm CGI remote execution.</desc>
<refs>
<ref source="BUGTRAQ">19950731 SECURITY HOLE: &quot;AnyForm&quot; CGI</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/719">719</ref>
<ref source="XF">http-cgi-anyform</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0067" seq="1999-0067">
<status>Entry</status>
<desc>phf CGI program allows remote command execution through shell metacharacters.</desc>
<refs>
<ref source="BUGTRAQ">19960923 PHF Attacks - Fun and games for the whole family</ref>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1996-06.html">CA-1996-06</ref>
<ref source="AUSCERT">AA-96.01</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/629">629</ref>
<ref source="OSVDB" url="http://www.osvdb.org/136">136</ref>
<ref source="XF">http-cgi-phf</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0068" seq="1999-0068">
<status>Entry</status>
<desc>CGI PHP mylog script allows an attacker to read any file on the target server.</desc>
<refs>
<ref source="BUGTRAQ">19971019 Vulnerability in PHP Example Logging Scripts</ref>
<ref source="XF">http-cgi-php-mylog</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/713">713</ref>
<ref source="OSVDB" url="http://www.osvdb.org/3396">3396</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0069" seq="1999-0069">
<status>Entry</status>
<desc>Solaris ufsrestore buffer overflow.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/169">00169</ref>
<ref source="XF">sun-ufsrestore</ref>
<ref source="OSVDB" url="http://www.osvdb.org/8158">8158</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0070" seq="1999-0070">
<status>Entry</status>
<desc>test-cgi program allows an attacker to list files on the server.</desc>
<refs>
<ref source="XF">http-cgi-test</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0071" seq="1999-0071">
<status>Entry</status>
<desc>Apache httpd cookie buffer overflow for versions 1.1.1 and earlier.</desc>
<refs>
<ref source="XF">http-apache-cookie</ref>
<ref source="NAI">NAI-2</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0072" seq="1999-0072">
<status>Entry</status>
<desc>Buffer overflow in AIX xdat gives root access to local users.</desc>
<refs>
<ref source="ERS">ERS-SVA-E01-1997:004.1</ref>
<ref source="XF">ibm-xdat</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0073" seq="1999-0073">
<status>Entry</status>
<desc>Telnet allows a remote client to specify environment variables including LD_LIBRARY_PATH, allowing an attacker to bypass the normal system libraries and gain root access.</desc>
<refs>
<ref source="CERT">CA-95:14.Telnetd_Environment_Vulnerability</ref>
<ref source="XF">linkerbug</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0074" seq="1999-0074">
<status>Entry</status>
<desc>Listening TCP ports are sequentially allocated, allowing spoofing attacks.</desc>
<refs>
<ref source="XF">seqport</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0075" seq="1999-0075">
<status>Entry</status>
<desc>PASV core dump in wu-ftpd daemon when attacker uses a QUOTE PASV command after specifying a username and password.</desc>
<refs>
<ref source="BUGTRAQ">19961016 Re: ftpd bug? Was: bin/1805: Bug in ftpd</ref>
<ref source="XF">ftp-pasvcore</ref>
<ref source="OSVDB" url="http://www.osvdb.org/5742">5742</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0076" seq="1999-0076">
<status>Candidate</status>
<phase date="19990925">Modified</phase>
<desc>Buffer overflow in wu-ftp from PASV command causes a core dump.</desc>
<refs>
<ref source="XF">ftp-args</ref>
</refs>
<votes>
<accept count="3">Ozancin, Baker, Frech</accept>
<noop count="1">Balinsky</noop>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Balinsky">Don't know what this is.  Is this the LIST Core dump vulnerability?</comment>
<comment voter="Christey">Need to add more references and details.</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0077" seq="1999-0077">
<status>Entry</status>
<desc>Predictable TCP sequence numbers allow spoofing.</desc>
<refs>
<ref source="XF" url="http://xforce.iss.net/static/139.php">tcp-seq-predict(139)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0078" seq="1999-0078">
<status>Candidate</status>
<phase date="19990621">Modified</phase>
<desc>pcnfsd (aka rpc.pcnfsd) allows local users to change file permissions, or execute arbitrary commands through arguments in the RPC call.</desc>
<refs>
<ref source="CERT">CA-96.08.pcnfsd</ref>
<ref source="XF">rpc-pcnfsd</ref>
</refs>
<votes>
<accept count="5">Collins, Northcutt, Landfield, Frech, Shostack</accept>
<noop count="1">Baker</noop>
<recast count="1">Christey</recast>
</votes>
<comments>
<comment voter="Christey">This candidate should be SPLIT, since there are two separate
software flaws.  One is a symlink race and the other is a
shell metacharacter problem.</comment>
<comment voter="Christey">The permissions part of this vulnerability appears to
overlap with CVE-1999-0353</comment>
<comment voter="Christey">SGI:20020802-01-I</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0079" seq="1999-0079">
<status>Entry</status>
<desc>Remote attackers can cause a denial of service in FTP by issuing multiple PASV commands, causing the server to run out of available ports.</desc>
<refs>
<ref source="XF">ftp-pasv-dos</ref>
<ref source="XF">ftp-pasvdos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0080" seq="1999-0080">
<status>Entry</status>
<desc>Certain configurations of wu-ftp FTP server 2.4 use a _PATH_EXECPATH setting to a directory with dangerous commands, such as /bin, which allows remote authenticated users to gain root access via the &quot;site exec&quot; command.</desc>
<refs>
<ref source="BUGTRAQ">19950531 SECURITY: problem with some wu-ftpd-2.4 binaries (fwd)</ref>
<ref source="CERT">CA-95:16.wu-ftpd.vul</ref>
<ref source="XF">ftp-execdotdot</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0081" seq="1999-0081">
<status>Entry</status>
<desc>wu-ftp allows files to be overwritten via the rnfr command.</desc>
<refs>
<ref source="XF">ftp-rnfr</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0082" seq="1999-0082">
<status>Entry</status>
<desc>CWD ~root command in ftpd allows root access.</desc>
<refs>
<ref source="XF">ftp-cwd</ref>
<ref source="FarmerVenema" url="http://www.alw.nih.gov/Security/Docs/admin-guide-to-cracking.101.html">Improving the Security of Your Site by Breaking Into it</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0083" seq="1999-0083">
<status>Entry</status>
<desc>getcwd() file descriptor leak in FTP.</desc>
<refs>
<ref source="XF">cwdleak</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0084" seq="1999-0084">
<status>Entry</status>
<desc>Certain NFS servers allow users to use mknod to gain privileges by creating a writable kmem device and setting the UID to 0.</desc>
<refs>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/78">nfs-mknod(78)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0085" seq="1999-0085">
<status>Entry</status>
<desc>Buffer overflow in rwhod on AIX and other operating systems allows remote attackers to execute arbitrary code via a UDP packet with a long hostname.</desc>
<refs>
<ref source="BUGTRAQ">19960821 rwhod buffer overflow</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/119">rwhod(119)</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/118">rwhod-vuln(118)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0086" seq="1999-0086">
<status>Candidate</status>
<phase date="19990630">Interim</phase>
<desc>AIX routed allows remote users to modify sensitive files.</desc>
<refs>
<ref source="ERS">ERS-SVA-E01-1998:001.1</ref>
<ref source="XF">ibm-routed</ref>
</refs>
<votes>
<accept count="2">Northcutt, Shostack</accept>
<modify count="2">Prosser, Frech</modify>
<noop count="1">Baker</noop>
<reject count="1">Christey</reject>
</votes>
<comments>
<comment voter="Frech">Reference: XF:ibm-routed</comment>
<comment voter="Prosser">This vulnerability allows debug mode to be turned on which is
the problem.  Should this be more specific in the description? This
one also affects SGI OSes, ref SGI Security Advisory 19981004-PX which
is in the SGI cluster, shouldn't these be cross-referenced as the same
vuln affects multiple OSes.</comment>
<comment voter="Christey">This appears to be subsumed by CVE-1999-0215</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0087" seq="1999-0087">
<status>Entry</status>
<desc>Denial of service in AIX telnet can freeze a system and prevent users from accessing the server.</desc>
<refs>
<ref source="XF">ibm-telnetdos</ref>
<ref source="ERS">ERS-SVA-E01-1998:003.1</ref>
<ref source="OSVDB" url="http://www.osvdb.org/7992">7992</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0088" seq="1999-0088">
<status>Candidate</status>
<phase date="19990617">Proposed</phase>
<desc>IRIX and AIX automountd services (autofsd) allow remote users to execute root commands.</desc>
<refs>
<ref source="ERS" url="http://www-1.ibm.com/services/brs/brspwhub.nsf/advisories/852567CC004F9038852566BF007B6393/$file/ERS-SVA-E01-1998_004_1.txt">ERS-SVA-E01-1998:004.1</ref>
</refs>
<votes>
<accept count="2">Northcutt, Shostack</accept>
<modify count="2">Prosser, Frech</modify>
<recast count="1">Baker</recast>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Frech">ERS (and other references, BTW) explicitly stipulate 'local and
remote'.
Reference: XF:irix-autofsd</comment>
<comment voter="Prosser">Include the SGI Alert as well since it is mentioned in the
description.
SGI Security Advisory 19981005-01-PX</comment>
<comment voter="Christey">DUPE CVE-1999-0210?</comment>
<comment voter="Christey">ADDREF CIAC:J-014</comment>
<comment voter="Baker">It does look very similar to 1999-0210.  Perhaps they should be a single entry</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0089" seq="1999-0089">
<status>Candidate</status>
<phase date="19990630">Interim</phase>
<desc>Buffer overflow in AIX libDtSvc library can allow local users to gain root access.</desc>
<refs>
<ref source="ERS">ERS-SVA-E01-1997:005.1</ref>
<ref source="XF">ibm-libDtSvc</ref>
</refs>
<votes>
<accept count="2">Northcutt, Shostack</accept>
<modify count="2">Prosser, Frech</modify>
<recast count="1">Baker</recast>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Frech">Reference: XF:ibm-libDtSvc</comment>
<comment voter="Prosser">The overflow is in the dtaction utility.  Also affects
dtaction in the CDE on versions of SunOS (SUN 164). Probably should be
specific.</comment>
<comment voter="Christey">Same Codebase as CVE-1999-0121, so the two entries should be
merged.</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0090" seq="1999-0090">
<status>Entry</status>
<desc>Buffer overflow in AIX rcp command allows local users to obtain root access.</desc>
<refs>
<ref source="ERS">ERS-SVA-E01-1997:005.1</ref>
<ref source="XF">ibm-rcp</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0091" seq="1999-0091">
<status>Entry</status>
<desc>Buffer overflow in AIX writesrv command allows local users to obtain root access.</desc>
<refs>
<ref source="ERS">ERS-SVA-E01-1997:005.1</ref>
<ref source="XF">ibm-writesrv</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0092" seq="1999-0092">
<status>Candidate</status>
<phase date="19990623">Proposed</phase>
<desc>Various vulnerabilities in the AIX portmir command allows local users to obtain root access.</desc>
<refs>
<ref source="ERS">ERS-SVA-E01-1997:006.1</ref>
</refs>
<votes>
<accept count="2">Baker, Bollinger</accept>
<modify count="1">Frech</modify>
<noop count="1">Ozancin</noop>
</votes>
<comments>
<comment voter="Frech">XF:ibm-portmir</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0093" seq="1999-0093">
<status>Entry</status>
<desc>AIX nslookup command allows local users to obtain root access by not dropping privileges correctly.</desc>
<refs>
<ref source="ERS">ERS-SVA-E01-1997:008.1</ref>
<ref source="XF">ibm-nslookup</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0094" seq="1999-0094">
<status>Entry</status>
<desc>AIX piodmgrsu command allows local users to gain additional group privileges.</desc>
<refs>
<ref source="ERS">ERS-SVA-E01-1997:007.1</ref>
<ref source="XF">ibm-piodmgrsu</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0095" seq="1999-0095">
<status>Entry</status>
<desc>The debug command in Sendmail is enabled, allowing attackers to execute commands as root.</desc>
<refs>
<ref source="CERT">CA-88.01</ref>
<ref source="CERT">CA-93.14</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1">1</ref>
<ref source="OSVDB" url="http://www.osvdb.org/195">195</ref>
<ref source="XF">smtp-debug</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0096" seq="1999-0096">
<status>Entry</status>
<desc>Sendmail decode alias can be used to overwrite sensitive files.</desc>
<refs>
<ref source="CERT">CA-93.16</ref>
<ref source="CERT">CA-95.05</ref>
<ref source="CIAC">A-13</ref>
<ref source="CIAC">A-14</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/122&amp;type=0&amp;nav=sec.sba">00122</ref>
<ref source="XF">smtp-dcod</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0097" seq="1999-0097">
<status>Entry</status>
<desc>The AIX FTP client can be forced to execute commands from a malicious server through shell metacharacters (e.g. a pipe character).</desc>
<refs>
<ref source="ERS">ERS-SVA-E01-1997:009.1</ref>
<ref source="XF">ibm-ftp</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0098" seq="1999-0098">
<status>Candidate</status>
<phase date="19990726">Proposed</phase>
<desc>Buffer overflow in SMTP HELO command in Sendmail allows a remote attacker to hide activities.</desc>
<refs>
<ref source="XF">smtp-helo-bo</ref>
</refs>
<votes>
<modify count="2">Baker, Frech</modify>
<noop count="1">Wall</noop>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Frech">(Accept XF reference.)
Our references do not mention hiding activities. This issue can crash the
SMTP server or execute arbitrary byte-code. Is there another reference
available?</comment>
<comment voter="Christey">Should this be merged with CVE-1999-0284, which is Sendmail
with SMTP HELO?</comment>
<comment voter="Christey">BUGTRAQ:19980522 about sendmail 8.8.8 HELO hole
http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221101925991&amp;w=2
BUGTRAQ:19980527 about sendmail 8.8.8 HELO hole
http://marc.theaimsgroup.com/?l=bugtraq&amp;m=90221101926003&amp;w=2</comment>
<comment voter="Baker">Apparently this XF reference is not for this issue, but for the other issue.  This should be modified to have the Bugtraq references, and remove the XF reference.</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0099" seq="1999-0099">
<status>Entry</status>
<desc>Buffer overflow in syslog utility allows local or remote attackers to gain root privileges.</desc>
<refs>
<ref source="CERT">CA-95.13.syslog.vul</ref>
<ref source="XF">smtp-syslog</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0100" seq="1999-0100">
<status>Entry</status>
<desc>Remote access in AIX innd 1.5.1, using control messages.</desc>
<refs>
<ref source="ERS">ERS-SVA-E01-1997:002.1</ref>
<ref source="XF">inn-controlmsg</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0101" seq="1999-0101">
<status>Entry</status>
<desc>Buffer overflow in AIX and Solaris &quot;gethostbyname&quot; library call allows root access through corrupt DNS host names.</desc>
<refs>
<ref source="ERS">ERS-SVA-E01-1997:001.1</ref>
<ref source="ERS">ERS-SVA-E01-1996:007.1</ref>
<ref source="SUN">00137a</ref>
<ref source="CIAC" url="http://ciac.llnl.gov/ciac/bulletins/h-13.shtml">H-13</ref>
<ref source="NAI">NAI-1</ref>
<ref source="XF">ghbn-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0102" seq="1999-0102">
<status>Entry</status>
<desc>Buffer overflow in SLmail 3.x allows attackers to execute commands using a large FROM line.</desc>
<refs>
<ref source="XF">slmail-fromheader-overflow</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0103" seq="1999-0103">
<status>Entry</status>
<desc>Echo and chargen, or other combinations of UDP services, can be used in tandem to flood the server, a.k.a. UDP bomb or UDP packet storm.</desc>
<refs>
<ref source="CERT">CA-96.01.UDP_service_denial</ref>
<ref source="XF">echo</ref>
<ref source="XF">chargen</ref>
<ref source="XF">chargen-patch</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0104" seq="1999-0104">
<status>Candidate</status>
<phase date="20040811">Modified</phase>
<desc>A later variation on the Teardrop IP denial of service attack, a.k.a. Teardrop-2.</desc>
<refs>
<ref source="CERT">CA-97.28.Teardrop_Land</ref>
<ref source="XF">teardrop-mod</ref>
</refs>
<votes>
<accept count="2">Wall, Frech</accept>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Wall">Another reference is Microsoft Knowledge Base Q179129.</comment>
<comment voter="Christey">Not sure how many separate &quot;instances&quot; of Teardrop there are.
See: CVE-1999-0015, CVE-1999-0104, CVE-1999-0257, CVE-1999-0258</comment>
<comment voter="Christey">See the SCO advisory at:
http://www.securityfocus.com/templates/advisory.html?id=1411
which may further clarify the issue.</comment>
<comment voter="Christey">MSKB:Q179129
http://support.microsoft.com/support/kb/articles/q179/1/29.asp</comment>
<comment voter="Christey">MSKB:Q179129
http://support.microsoft.com/support/kb/articles/q179/1/29.asp
Note that the hotfix name is teardrop2, but the keywords
included in the KB article specifically name bonk
(CVE-1999-0258) and boink.
Since teardrop2 was fixed in a slightly different version
(at least in a separate patch) than Teardrop, CD:SF-LOC
suggests keeping them separate.</comment>
<comment voter="Christey">Add period to the end of the description.</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0105" seq="1999-0105">
<status>Candidate</status>
<phase date="19990726">Proposed</phase>
<desc>finger allows recursive searches by using a long string of @ symbols.</desc>
<refs>
</refs>
<votes>
<modify count="3">Shostack, Baker, Frech</modify>
<noop count="1">Christey</noop>
<reject count="1">Northcutt</reject>
</votes>
<comments>
<comment voter="Shostack">fingerD</comment>
<comment voter="Frech">XF:finger-bomb</comment>
<comment voter="Christey">aka redirection or forwarding requests? (but then might
overlap CVE-1999-0106)</comment>
<comment voter="Baker">should change description to indicate the recursive searching can consume enough system resources to cause a DoS.</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0106" seq="1999-0106">
<status>Candidate</status>
<phase date="19990726">Proposed</phase>
<desc>Finger redirection allows finger bombs.</desc>
<refs>
</refs>
<votes>
<accept count="1">Northcutt</accept>
<modify count="2">Shostack, Frech</modify>
<recast count="1">Baker</recast>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Shostack">fingerd allows redirection
This is a larger modification, since there are two applications of the 
vulnerability, one that I can finger anonymously, and the other that I 
can finger bomb anonymously.</comment>
<comment voter="Frech">XF:finger-bomb</comment>
<comment voter="Christey">need more refs</comment>
<comment voter="Baker">This should be merged with 1999-0105</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0107" seq="1999-0107">
<status>Candidate</status>
<phase date="19991223">Modified</phase>
<desc>Buffer overflow in Apache 1.2.5 and earlier allows a remote attacker to cause a denial of service with a large number of GET requests containing a large number of / characters.</desc>
<refs>
<ref source="XF">apache-dos</ref>
<ref source="BUGTRAQ">19971230 Apache DoS attack?</ref>
</refs>
<votes>
<accept count="1">Baker</accept>
<modify count="1">Frech</modify>
<noop count="3">Shostack, Northcutt, Wall</noop>
<reviewing count="1">Levy</reviewing>
<revote count="1">Christey</revote>
</votes>
<comments>
<comment voter="Wall">- Although this is probably the phf hack.</comment>
<comment voter="Frech">XF:apache-dos</comment>
<comment voter="Christey">This sounds like the incident reported in:
NTBUGTRAQ:20000810 Apache Distributed Denial of Service</comment>
<comment voter="Levy">I belive this is the problem where sending lot of HTTP headers to apache resulted on a denial of service.
BUGTRAQ: http://www.securityfocus.com/archive/1/10228
BUGTRAQ: http://www.securityfocus.com/archive/1/10516</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0108" seq="1999-0108">
<status>Entry</status>
<desc>The printers program in IRIX has a buffer overflow that gives root access to local users.</desc>
<refs>
<ref source="BUGTRAQ">another day, another buffer overflow...</ref>
<ref source="XF">printers-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0109" seq="1999-0109">
<status>Entry</status>
<desc>Buffer overflow in ffbconfig in Solaris 2.5.1.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/140">00140</ref>
<ref source="AUSCERT">AA-97.06</ref>
<ref source="XF">ffbconfig-bo</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0110" seq="1999-0110">
<status>Candidate</status>
<phase date="19990810">Interim</phase>
<desc>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-1999-0315.  Reason: This candidate's original description had a typo that delayed it from being detected as a duplicate of CVE-1999-0315.  Notes: All CVE users should reference CVE-1999-0315 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</desc>
<refs>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="4">Shostack, Levy, Northcutt, Wall</noop>
<reject count="3">Dik, Christey, Baker</reject>
</votes>
<comments>
<comment voter="Frech">XF:fdformat-bo</comment>
<comment voter="Christey">Duplicate of CVE-1999-0315</comment>
<comment voter="Dik">dup</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0111" seq="1999-0111">
<status>Entry</status>
<desc>RIP v1 is susceptible to spoofing.</desc>
<refs>
<ref source="XF">rip</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0112" seq="1999-0112">
<status>Entry</status>
<desc>Buffer overflow in AIX dtterm program for the CDE.</desc>
<refs>
<ref source="BUGTRAQ">19970520 AIX 4.2 dtterm exploit</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/878">dtterm-bo(878)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0113" seq="1999-0113">
<status>Entry</status>
<desc>Some implementations of rlogin allow root access if given a -froot parameter.</desc>
<refs>
<ref source="BUGTRAQ">19940729 -froot??? (AIX rlogin bug)</ref>
<ref source="CERT">CA-94.09.bin.login.vulnerability</ref>
<ref source="CIAC">E-26</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/458">458</ref>
<ref source="XF">rlogin-froot</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0114" seq="1999-0114">
<status>Candidate</status>
<phase date="20000106">Modified</phase>
<desc>Local users can execute commands as other users, and read other users' files, through the filter command in the Elm elm-2.4 mail package using a symlink attack.</desc>
<refs>
<ref source="BUGTRAQ">19990912 elm filter program</ref>
<ref source="BUGTRAQ">19951226 filter (elm package) security hole</ref>
<ref source="XF">elm-filter2</ref>
</refs>
<votes>
<accept count="7">Shostack, Bishop, Blake, Wall, Landfield, Cole, Armstrong</accept>
<modify count="2">Baker, Frech</modify>
<noop count="3">Ozancin, Christey, Northcutt</noop>
<reviewing count="1">Levy</reviewing>
</votes>
<comments>
<comment voter="Frech">XF:elm-filter2</comment>
<comment voter="CHANGE">[Wall changed vote from NOOP to ACCEPT]</comment>
<comment voter="Landfield">with Frech modifications</comment>
<comment voter="Baker">ADD REF http://www.cert.org/ftp/cert_bulletins/VB-95:10a.elm	Official Advisory</comment>
<comment voter="Christey">The correct URL is http://www.cert.org/vendor_bulletins/VB-95:10a.elm
Need to make sure that this CERT advisory describes the right
problem, especially since the CERT advisory is dated December
18, 1995 and the original Bugtraq post was December 26, 1995.</comment>
<comment voter="Christey">BID:1802
URL:http://www.securityfocus.com/bid/1802
BID:1802 doesn't include the 1999 posting - does Security
Focus think that the 1999 post describes a different
vulnerability?</comment>
<comment voter="Christey">XF:elm-filter2 isn't on the X-Force web site.  How about XF:elm-filter(402) ?
Its references point to the December 26, 1995 BUgtraq post.

Also consider CIAC:G-36 and CERT:VB-95:10</comment>
<comment voter="Frech">DELREF:XF:elm-filter2(711)
ADDREF:XF:elm-filter(402)</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0115" seq="1999-0115">
<status>Entry</status>
<desc>AIX bugfiler program allows local users to gain root access.</desc>
<refs>
<ref source="BUGTRAQ">19970909 AIX bugfiler</ref>
<ref source="XF">ibm-bugfiler</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1800">1800</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0116" seq="1999-0116">
<status>Entry</status>
<desc>Denial of service when an attacker sends many SYN packets to create multiple connections without ever sending an ACK to complete the connection, aka SYN flood.</desc>
<refs>
<ref source="CERT">CA-96.21.tcp_syn.flooding</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19961202-01-PX">19961202-01-PX</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/136">00136</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0117" seq="1999-0117">
<status>Entry</status>
<desc>AIX passwd allows local users to gain root access.</desc>
<refs>
<ref source="XF">ibm-passwd</ref>
<ref source="CERT">CA-92:07.AIX.passwd.vulnerability</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0118" seq="1999-0118">
<status>Entry</status>
<desc>AIX infod allows local users to gain root access through an X display.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91158980826979&amp;w=2">19981119 RSI.0011.11-09-98.AIX.INFOD</ref>
<ref source="XF">aix-infod</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0119" seq="1999-0119">
<status>Candidate</status>
<phase date="19990728">Proposed</phase>
<desc>Windows NT 4.0 beta allows users to read and delete shares.</desc>
<refs>
</refs>
<votes>
<modify count="1">Frech</modify>
<noop count="2">Northcutt, Baker</noop>
<reject count="1">Wall</reject>
</votes>
<comments>
<comment voter="Wall">Reject based on beta copy.</comment>
<comment voter="Frech">XF:nt-beta(11)
Reconsider reject, because this beta was in widespread use.</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0120" seq="1999-0120">
<status>Entry</status>
<desc>Sun/Solaris utmp file allows local users to gain root access if it is writable by users other than root.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/126">00126</ref>
<ref source="CERT">CA-94.06.utmp.vulnerability</ref>
<ref source="XF">utmp-write</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0121" seq="1999-0121">
<status>Candidate</status>
<phase date="19990617">Proposed</phase>
<desc>Buffer overflow in dtaction command gives root access.</desc>
<refs>
<ref source="SUN">00164</ref>
<ref source="ERS">ERS-SVA-E01-1997:005.1</ref>
</refs>
<votes>
<accept count="2">Dik, Northcutt</accept>
<modify count="3">Prosser, Baker, Frech</modify>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Frech">Reference: XF:dtaction-bo
Reference: XF:sun-dtaction</comment>
<comment voter="Prosser">Buffer overflow also affects /usr/dt/bin/dtaction in libDtSvc.a
library in AIX 4.x, but reference for this Sun vulnerability should
only reflect the Sun Bulletin or the CIAC I-032 version of the Sun
Bulletin</comment>
<comment voter="Christey">This is the Same Codebase as CVE-1999-0089, so the two entries
should be merged.</comment>
<comment voter="Frech">Replace sun-dtaction(732) with dtaction-bo(879)</comment>
<comment voter="Baker">Merge with 1999-0089</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0122" seq="1999-0122">
<status>Entry</status>
<desc>Buffer overflow in AIX lchangelv gives root access.</desc>
<refs>
<ref source="BUGTRAQ">Jul21,1999</ref>
<ref source="XF">lchangelv-bo</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0123" seq="1999-0123">
<status>Candidate</status>
<phase date="20000105">Modified</phase>
<desc>Race condition in Linux mailx command allows local users to read user files.</desc>
<refs>
<ref source="XF">linux-mailx</ref>
<ref source="BUGTRAQ">19951222 mailx-5.5 (slackware /bin/mail) security hole</ref>
</refs>
<votes>
<accept count="3">Ozancin, Baker, Frech</accept>
<noop count="1">Wall</noop>
</votes>
<comments>
</comments>
</item>

<item type="CVE" name="CVE-1999-0124" seq="1999-0124">
<status>Entry</status>
<desc>Vulnerabilities in UMN gopher and gopher+ versions 1.12 and 2.0x allow an intruder to read any files that can be accessed by the gopher daemon.</desc>
<refs>
<ref source="CERT">CA-93:11.UMN.UNIX.gopher.vulnerability</ref>
<ref source="XF">gopher-vuln</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0125" seq="1999-0125">
<status>Entry</status>
<desc>Buffer overflow in SGI IRIX mailx program.</desc>
<refs>
<ref source="XF">sgi-mailx-bo</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19980605-01-PX">19980605-01-PX</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0126" seq="1999-0126">
<status>Entry</status>
<desc>SGI IRIX buffer overflow in xterm and Xaw allows root access.</desc>
<refs>
<ref source="CERT">VB-98.04.xterm.Xaw</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-010.shtml">J-010</ref>
<ref source="XF">xfree86-xterm-xaw</ref>
<ref source="XF">xfree86-xaw</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0127" seq="1999-0127">
<status>Candidate</status>
<phase date="19990623">Proposed</phase>
<desc>swinstall and swmodify commands in SD-UX package in HP-UX systems allow local users to create or overwrite arbitrary files to gain root access.</desc>
<refs>
<ref source="CERT">CA-96.27.hp_sw_install</ref>
<ref source="AUSCERT">AA-96.04</ref>
<ref source="XF">hpux-swinstall</ref>
</refs>
<votes>
<accept count="2">Prosser, Baker</accept>
<modify count="1">Frech</modify>
<noop count="1">Christey</noop>
</votes>
<comments>
<comment voter="Frech">(keep current XF: reference, and add)
XF:hpux-sqwmodify</comment>
<comment voter="Christey">Perhaps this should be split, per SF-LOC.</comment>
<comment voter="Christey">CIAC:H-81
http://ciac.llnl.gov/ciac/bulletins/h-81.shtml
HP:HPSBUX9707-064  references CERT:CA-96.27
http://ciac.llnl.gov/ciac/bulletins/h-81.shtml

The original AUSCERT advisory says that the programs &quot;create
files in an insecure manner&quot; and &quot;Exploit details involving
this vulnerability have been made publicly available.&quot; which
leads one to assume that the following original Bugtraq post
provides the details for a standard symlink problem:

BUGTRAQ:19961005 swinst,bug
http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602167419941&amp;w=2</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0128" seq="1999-0128">
<status>Entry</status>
<desc>Oversized ICMP ping packets can result in a denial of service, aka Ping o' Death.</desc>
<refs>
<ref source="XF">ping-death</ref>
<ref source="CERT">CA-96.26.ping</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0129" seq="1999-0129">
<status>Entry</status>
<desc>Sendmail allows local users to write to a file and gain group permissions via a .forward or :include: file.</desc>
<refs>
<ref source="CERT">CA-96.25.sendmail_groups</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0130" seq="1999-0130">
<status>Entry</status>
<desc>Local users can start Sendmail in daemon mode and gain root privileges.</desc>
<refs>
<ref source="CERT">CA-96.24.sendmail.daemon.mode</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/716">716</ref>
<ref source="XF">sendmail-daemon-mode</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0131" seq="1999-0131">
<status>Entry</status>
<desc>Buffer overflow and denial of service in Sendmail 8.7.5 and earlier through GECOS field gives root access to local users.</desc>
<refs>
<ref source="CERT">CA-96.20.sendmail_vul</ref>
<ref source="XF">smtp-875bo</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/717">717</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0132" seq="1999-0132">
<status>Entry</status>
<desc>Expreserve, as used in vi and ex, allows local users to overwrite arbitrary files and gain root access.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1996-19.html">CA-1996-19</ref>
<ref source="OSVDB" url="http://www.osvdb.org/11723">11723</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/401">expreserve(401)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0133" seq="1999-0133">
<status>Entry</status>
<desc>fm_fls license server for Adobe Framemaker allows local users to overwrite arbitrary files and gain root access.</desc>
<refs>
<ref source="CERT">CA-96.18.fm_fls</ref>
<ref source="XF">fmaker-logfile</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0134" seq="1999-0134">
<status>Entry</status>
<desc>vold in Solaris 2.x allows local users to gain root access.</desc>
<refs>
<ref source="XF">sol-voldtmp</ref>
<ref source="CERT">CA-96.17.Solaris_vold_vul</ref>
<ref source="AUSCERT">AL-96.04</ref>
<ref source="OSVDB" url="http://www.osvdb.org/8159">8159</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0135" seq="1999-0135">
<status>Entry</status>
<desc>admintool in Solaris allows a local user to write to arbitrary files and gain root access.</desc>
<refs>
<ref source="XF">sun-admintool</ref>
<ref source="CERT">CA-96.16.Solaris_admintool_vul</ref>
<ref source="AUSCERT">AL-96.03</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0136" seq="1999-0136">
<status>Entry</status>
<desc>Kodak Color Management System (KCMS) on Solaris allows a local user to write to arbitrary files and gain root access.</desc>
<refs>
<ref source="XF">sol-KCMSvuln</ref>
<ref source="AUSCERT">AL-96.02</ref>
<ref source="CERT">CA-96.15.Solaris_KCMS_vul</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0137" seq="1999-0137">
<status>Entry</status>
<desc>The dip program on many Linux systems allows local users to gain root access via a buffer overflow.</desc>
<refs>
<ref source="XF">linux-dipbo</ref>
<ref source="CERT">CA-96.13.dip_vul</ref>
<ref source="XF">dip-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0138" seq="1999-0138">
<status>Entry</status>
<desc>The suidperl and sperl program do not give up root privileges when changing UIDs back to the original users, allowing root access.</desc>
<refs>
<ref source="CERT">CA-96.12.suidperl_vul</ref>
<ref source="XF">sperl-suid</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0139" seq="1999-0139">
<status>Entry</status>
<desc>Buffer overflow in Solaris x86 mkcookie allows local users to obtain root access.</desc>
<refs>
<ref source="XF">sol-mkcookie</ref>
<ref source="RSI">RSI.0012.12-03-98.SOLARIS.MKCOOKIE</ref>
<ref source="OSVDB" url="http://www.osvdb.org/8205">8205</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0140" seq="1999-0140">
<status>Candidate</status>
<phase date="19990630">Proposed</phase>
<desc>Denial of service in RAS/PPTP on NT systems.</desc>
<refs>
</refs>
<votes>
<accept count="1">Hill</accept>
<modify count="2">Frech, Meunier</modify>
<noop count="1">Baker</noop>
<reject count="1">Christey</reject>
</votes>
<comments>
<comment voter="Meunier">Add &quot;pptp invalid packet length in header&quot; to distinguish from other
vulnerabilities in RAS/PPTP on NT systems resulting in DOS, that might be
discovered in the future.</comment>
<comment voter="Frech">XF:nt-ras-bo
ONLY IF reference is to MS:MS99-016</comment>
<comment voter="Christey">According to my mappings, this is not the MS:MS99-016 problem
referred to by Andre.  However, I have yet to dig up a
source.</comment>
<comment voter="CHANGE">[Christey changed vote from NOOP to REVIEWING]</comment>
<comment voter="CHANGE">[Christey changed vote from REVIEWING to REJECT]</comment>
<comment voter="Christey">This is too general to know which problem is being discussed.
More precise candidates should be created.</comment>
<comment voter="Christey">Consider adding BID:2111</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0141" seq="1999-0141">
<status>Entry</status>
<desc>Java Bytecode Verifier allows malicious applets to execute arbitrary commands as the user of the applet.</desc>
<refs>
<ref source="XF">http-java-applet</ref>
<ref source="CERT">CA-96.07.java_bytecode_verifier</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/134">00134</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0142" seq="1999-0142">
<status>Entry</status>
<desc>The Java Applet Security Manager implementation in Netscape Navigator 2.0 and Java Developer's Kit 1.0 allows an applet to connect to arbitrary hosts.</desc>
<refs>
<ref source="CERT">CA-96.05.java_applet_security_mgr</ref>
<ref source="XF">http-java-appletsecmgr</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0143" seq="1999-0143">
<status>Entry</status>
<desc>Kerberos 4 key servers allow a user to masquerade as another by breaking and generating session keys.</desc>
<refs>
<ref source="CERT">CA-96.03.kerberos_4_key_server</ref>
<ref source="XF">kerberos-bf</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0144" seq="1999-0144">
<status>Candidate</status>
<phase date="20010301">Modified</phase>
<desc>Denial of service in Qmail by specifying a large number of recipients with the RCPT command.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602558319024&amp;w=2">19970612 qmail-dos-2.c, another denial of service attack</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=87602558319029&amp;w=2">19970612 Re: Denial of service (qmail-smtpd)</ref>
<ref source="MISC" url="http://cr.yp.to/qmail/venema.html">http://cr.yp.to/qmail/venema.html</ref>
<ref source="MISC" url="http://www.ornl.gov/its/archives/mailing-lists/qmail/1997/06/threads.html">http://www.ornl.gov/its/archives/mailing-lists/qmail/1997/06/threads.html</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2237">2237</ref>
<ref source="XF" url="http://xforce.iss.net/static/208.php">qmail-rcpt</ref>
</refs>
<votes>
<accept count="4">Frech, Meunier, Hill, Baker</accept>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Christey">DUPE CVE-1999-0418 and CVE-1999-0250?</comment>
<comment voter="Christey">Dan Bernstein, author of Qmail, says that this is not a
vulnerability in qmail because Unix has built-in resource
limits that can restrict the size of a qmail process; other
limits can be specified by the administrator.  See
http://cr.yp.to/qmail/venema.html

Significant discussion of this issue took place on the qmail
list.  The fundamental question appears to be whether 
application software should set its own limits, or rely
on limits set by the parent operating system (in this case,
UNIX).  Also, some people said that the only problem was that
the suggested configuration was not well documented, but this
was refuted by others.

See the following threads at
http://www.ornl.gov/its/archives/mailing-lists/qmail/1997/06/threads.html
&quot;Denial of service (qmail-smtpd)&quot;
&quot;qmail-dos-2.c, another denial of service&quot;
&quot;[PATCH] denial of service&quot;
&quot;just another qmail denial-of-service&quot;
&quot;the UNIX way&quot;
&quot;Time for a reality check&quot;

Also see Bugtraq threads on a different vulnerability that
is related to this topic:
BUGTRAQ:19990903 Web servers / possible DOS Attack / mime header flooding
http://archives.neohapsis.com/archives/bugtraq/1998_3/0742.html</comment>
<comment voter="Baker">http://cr.yp.to/qmail/venema.html
Berstein rejects this as a vulnerability, claiming this is a slander campaign by Wietse Venema.
His page states this is not a qmail problem, rather it is a UNIX problem
that many apps can consume all available memory, and that the administrator
is responsible to set limits in the OS, rather than expect applications to
individually prevent memory exhaustion.  CAN 1999-0250 does appear to
be a duplicate of this entry, based on the research I have done so far.
There were two different bugtraq postings, but the second one references
the first, stating that the new exploit uses perl instead of shell scripting
to accomplish the same attack/exploit.</comment>
<comment voter="Baker">http://www.securityfocus.com/archive/1/6970
http://www.securityfocus.com/archive/1/6969
http://cr.yp.to/qmail/venema.html

Should probably reject CVE-1999-0250, and add these references to this
Candidate.</comment>
<comment voter="Baker">http://www.securityfocus.com/bid/2237</comment>
<comment voter="CHANGE">[Baker changed vote from REVIEWING to ACCEPT]</comment>
<comment voter="Christey">qmail-dos-1.c, as published by Wietse Venema (CVE-1999-0250)
in &quot;BUGTRAQ:19970612 Denial of service (qmail-smtpd)&quot;, does not
use any RCPT commands.  Instead, it sends long strings
of &quot;X&quot; characters.  A followup by &quot;super@UFO.ORG&quot; includes
an exploit that claims to do the same thing; however, that
exploit does not send long strings of X characters - it sends
a large number of RCPT commands.  It appears that super@ufo.org
followed up to the wrong message.

NOTE: the ufo.org domain was purchased by another party in
2003, so the current owner is not associated with any
statements by &quot;super@ufo.org&quot; that were made before 2003.

qmail-dos-2.c, as published by Wietse Venema (CVE-1999-0144)
in &quot;BUGTRAQ:19970612 qmail-dos-2.c, another denial of service attack&quot;
sends a large number of RCPT commands.

ADDREF BID:2237
ADDREF BUGTRAQ:19970612 qmail-dos-2.c, another denial of service attack
ADDREF BUGTRAQ:19970612 Re: Denial of service (qmail-smtpd)

Also see a related thread:
BUGTRAQ:19990308 SMTP server account probing
http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92100018214316&amp;w=2

This also describes a problem with mail servers not being able
to handle too many &quot;RCPT TO&quot; requests.  A followup message
notes that application-level protection is used in Sendmail
to prevent this:
BUGTRAQ:19990309 Re: SMTP server account probing
http://marc.theaimsgroup.com/?l=bugtraq&amp;m=92101584629263&amp;w=2
The person further says, &quot;This attack can easily be
prevented with configuration methods.&quot;</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0145" seq="1999-0145">
<status>Entry</status>
<desc>Sendmail WIZ command enabled, allowing root access.</desc>
<refs>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1990-11.html">CA-1990-11</ref>
<ref source="CERT" url="http://www.cert.org/advisories/CA-1993-14.html">CA-1993-14</ref>
<ref source="BUGTRAQ" url="http://www2.dataguard.no/bugtraq/1995_1/0332.html">19950206 sendmail wizard thing...</ref>
<ref source="FarmerVenema" url="http://www.alw.nih.gov/Security/Docs/admin-guide-to-cracking.101.html">Improving the Security of Your Site by Breaking Into it</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0146" seq="1999-0146">
<status>Entry</status>
<desc>The campas CGI program provided with some NCSA web servers allows an attacker to execute arbitrary commands via encoded carriage return characters in the query string, as demonstrated by reading the password file.</desc>
<refs>
<ref source="BUGTRAQ">19970715 Bug CGI campas</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1975">1975</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/298">http-cgi-campas(298)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0147" seq="1999-0147">
<status>Entry</status>
<desc>The aglimpse CGI program of the Glimpse package allows remote execution of arbitrary commands.</desc>
<refs>
<ref source="XF">http-cgi-glimpse</ref>
<ref source="AUSCERT">AA-97.28</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0148" seq="1999-0148">
<status>Entry</status>
<desc>The handler CGI program in IRIX allows arbitrary command execution.</desc>
<refs>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19970501-02-PX">19970501-02-PX</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/380">380</ref>
<ref source="XF">http-sgi-handler</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0149" seq="1999-0149">
<status>Entry</status>
<desc>The wrap CGI program in IRIX allows remote attackers to view arbitrary directory listings via a .. (dot dot) attack.</desc>
<refs>
<ref source="BUGTRAQ">19970420 IRIX 6.x /cgi-bin/wrap bug</ref>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19970501-02-PX">19970501-02-PX</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/373">373</ref>
<ref source="OSVDB" url="http://www.osvdb.org/247">247</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/290">http-sgi-wrap(290)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0150" seq="1999-0150">
<status>Entry</status>
<desc>The Perl fingerd program allows arbitrary command execution from remote users.</desc>
<refs>
<ref source="XF">perl-fingerd</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0151" seq="1999-0151">
<status>Entry</status>
<desc>The SATAN session key may be disclosed if the user points the web browser to other sites, possibly allowing root access.</desc>
<refs>
<ref source="CERT">CA-95.07a.REVISED.satan.vul</ref>
<ref source="CERT">CA-95.06.satan.vul</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0152" seq="1999-0152">
<status>Entry</status>
<desc>The DG/UX finger daemon allows remote command execution through shell metacharacters.</desc>
<refs>
<ref source="BUGTRAQ">19970811 dgux in.fingerd vulnerability</ref>
<ref source="XF">dgux-fingerd</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0153" seq="1999-0153">
<status>Entry</status>
<desc>Windows 95/NT out of band (OOB) data denial of service through NETBIOS port, aka WinNuke.</desc>
<refs>
<ref source="XF">win-oob</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1666">1666</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0154" seq="1999-0154">
<status>Candidate</status>
<phase date="20010912">Proposed</phase>
<desc>IIS 2.0 and 3.0 allows remote attackers to read the source code for ASP pages by appending a . (dot) to the end of the URL.</desc>
<refs>
<ref source="MSKB">Q163485</ref>
<ref source="MSKB">Q164059</ref>
<ref source="BUGTRAQ">19970220 ! [ADVISORY] Major Security Hole in MS ASP</ref>
<ref source="XF">http-iis-aspdot</ref>
<ref source="XF">http-iis-aspsource</ref>
</refs>
<votes>
<accept count="4">Frech, Stracener, Wall, Foat</accept>
<noop count="3">Christey, Baker, Cole</noop>
</votes>
<comments>
<comment voter="Christey">This is the precursor to the problem that is identified in
CVE-1999-0253.  </comment>
<comment voter="Christey">CIAC:H-48
URL:http://ciac.llnl.gov/ciac/bulletins/h-48.shtml</comment>
<comment voter="CHANGE">[Foat changed vote from NOOP to ACCEPT]</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0155" seq="1999-0155">
<status>Entry</status>
<desc>The ghostscript command with the -dSAFER option allows remote attackers to execute commands.</desc>
<refs>
<ref source="XF">gscript-dsafer</ref>
<ref source="CERT">CA-95.10.ghostscript</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0156" seq="1999-0156">
<status>Candidate</status>
<phase date="19990714">Proposed</phase>
<desc>wu-ftpd FTP daemon allows any user and password combination.</desc>
<refs>
<ref source="XF">ftp-pwless</ref>
</refs>
<votes>
<accept count="2">Shostack, Northcutt</accept>
<noop count="1">Baker</noop>
<recast count="1">Frech</recast>
<reviewing count="2">Christey, Prosser</reviewing>
</votes>
<comments>
<comment voter="Prosser">but so far can find no reference to this one</comment>
<comment voter="Frech">Our records indicate that this does not necessarly affect just wu-ftp (ie,
also affects IIS FTP server).</comment>
<comment voter="Christey">The references for XF:ftp-pwless are not specific enough,
e.g. in terms of version numbers.  Perhaps this candidate
should be rejected due to insufficient information.</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0157" seq="1999-0157">
<status>Entry</status>
<desc>Cisco PIX firewall and CBAC IP fragmentation attack results in a denial of service.</desc>
<refs>
<ref source="CISCO">http://www.cisco.com/warp/public/770/nifrag.shtml</ref>
<ref source="XF">cisco-fragmented-attacks</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1097">1097</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0158" seq="1999-0158">
<status>Entry</status>
<desc>Cisco PIX firewall manager (PFM) on Windows NT allows attackers to connect to port 8080 on the PFM server and retrieve any file whose name and location is known.</desc>
<refs>
<ref source="CISCO" url="http://www.cisco.com/warp/public/770/pixmgrfile-pub.shtml">20010913 Cisco PIX Firewall Manager File Exposure</ref>
<ref source="XF">cisco-pix-file-exposure</ref>
<ref source="OSVDB" url="http://www.osvdb.org/685">685</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0159" seq="1999-0159">
<status>Entry</status>
<desc>Attackers can crash a Cisco IOS router or device, provided they can get to an interactive prompt (such as a login).  This applies to some IOS 9.x, 10.x, and 11.x releases.</desc>
<refs>
<ref source="CISCO">http://www.cisco.com/warp/public/770/ioslogin-pub.shtml</ref>
<ref source="XF">cisco-ios-crash</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0160" seq="1999-0160">
<status>Entry</status>
<desc>Some classic Cisco IOS devices have a vulnerability in the PPP CHAP authentication to establish unauthorized PPP connections.</desc>
<refs>
<ref source="CISCO">19971001 Vulnerabilities in Cisco CHAP Authentication</ref>
<ref source="CIAC">I-002A</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1099">1099</ref>
<ref source="XF">cisco-chap</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0161" seq="1999-0161">
<status>Entry</status>
<desc>In Cisco IOS 10.3, with the tacacs-ds or tacacs keyword, an extended IP access control list could bypass filtering.</desc>
<refs>
<ref source="CISCO">http://www.cisco.com/warp/public/707/1.html</ref>
<ref source="XF">cisco-acl-tacacs</ref>
<ref source="OSVDB" url="http://www.osvdb.org/797">797</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0162" seq="1999-0162">
<status>Entry</status>
<desc>The &quot;established&quot; keyword in some Cisco IOS software allowed an attacker to bypass filtering.</desc>
<refs>
<ref source="CISCO">19950601 &quot;Established&quot; Keyword May Allow Packets to Bypass Filter</ref>
<ref source="XF">cisco-acl-established</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0163" seq="1999-0163">
<status>Candidate</status>
<phase date="19990714">Proposed</phase>
<desc>In older versions of Sendmail, an attacker could use a pipe character to execute root commands.</desc>
<refs>
<ref source="XF">smtp-pipe</ref>
</refs>
<votes>
<accept count="2">Frech, Northcutt</accept>
<modify count="1">Prosser</modify>
<noop count="2">Christey, Baker</noop>
<recast count="1">Shostack</recast>
</votes>
<comments>
<comment voter="Shostack">there was a 'To: |' and a 'From: |' attack, which I
think are seperate.</comment>
<comment voter="Prosser">older vulnerability, but one additional reference is-
The Ultimate Sendmail Hole List by Markus H&#252;bner @
bau2.uibk.ac.at/matic/buglist.htm
'|PROGRAM '</comment>
<comment voter="Christey">Description needs to be more specific to distinguish between
this and CVE-1999-0203, as alluded to by Adam Shostack</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0164" seq="1999-0164">
<status>Entry</status>
<desc>A race condition in the Solaris ps command allows an attacker to overwrite critical files.</desc>
<refs>
<ref source="XF">sol-pstmprace</ref>
<ref source="AUSCERT">AA-95.07</ref>
<ref source="CERT">CA-95.09.Solaris.ps.vul</ref>
<ref source="OSVDB" url="http://www.osvdb.org/8346">8346</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0165" seq="1999-0165">
<status>Candidate</status>
<phase date="20040811">Modified</phase>
<desc>NFS cache poisoning.</desc>
<refs>
<ref source="XF">nfs-cache</ref>
</refs>
<votes>
<accept count="3">Frech, Northcutt, Baker</accept>
<modify count="1">Shostack</modify>
<noop count="1">Prosser</noop>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Shostack">need more data</comment>
<comment voter="Christey">need more refs</comment>
<comment voter="Christey">Add period to the end of the description.</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0166" seq="1999-0166">
<status>Entry</status>
<desc>NFS allows users to use a &quot;cd ..&quot; command to access other directories besides the exported file system.</desc>
<refs>
<ref source="XF">nfs-cd</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0167" seq="1999-0167">
<status>Entry</status>
<desc>In SunOS, NFS file handles could be guessed, giving unauthorized access to the exported file system.</desc>
<refs>
<ref source="XF">nfs-guess</ref>
<ref source="CERT">CA-91.21.SunOS.NFS.Jumbo.and.fsirand</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0168" seq="1999-0168">
<status>Entry</status>
<desc>The portmapper may act as a proxy and redirect service requests from an attacker, making the request appear to come from the local host, possibly bypassing authentication that would otherwise have taken place.  For example, NFS file systems could be mounted through the portmapper despite export restrictions.</desc>
<refs>
<ref source="XF">nfs-portmap</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0169" seq="1999-0169">
<status>Candidate</status>
<phase date="19990714">Proposed</phase>
<desc>NFS allows attackers to read and write any file on the system by specifying a false UID.</desc>
<refs>
<ref source="XF">nfs-uid</ref>
</refs>
<votes>
<accept count="2">Frech, Northcutt</accept>
<modify count="1">Baker</modify>
<reject count="1">Shostack</reject>
</votes>
<comments>
<comment voter="Shostack">this is not a vulnerability but a design feature.</comment>
<comment voter="Baker">Maybe we should reword it so that it is clear that this was a problem to something like:

&quot;A remote attacker could read/write files to the system with root-level permissions on NFS servers that fail to properly check the UID.&quot;</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0170" seq="1999-0170">
<status>Entry</status>
<desc>Remote attackers can mount an NFS file system in Ultrix or OSF, even if it is denied on the access list.</desc>
<refs>
<ref source="XF">nfs-ultrix</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0171" seq="1999-0171">
<status>Candidate</status>
<phase date="19990714">Proposed</phase>
<desc>Denial of service in syslog by sending it a large number of superfluous messages.</desc>
<refs>
<ref source="XF">syslog-flood</ref>
</refs>
<votes>
<accept count="2">Frech, Northcutt</accept>
<noop count="1">Baker</noop>
<reject count="2">Shostack, Christey</reject>
</votes>
<comments>
<comment voter="Shostack">design issue, not a vulnerability.  Alternately, add:
DOS on server by opening a large number of telnet sessions..</comment>
<comment voter="Christey">Duplicate of CVE-1999-0566</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0172" seq="1999-0172">
<status>Entry</status>
<desc>FormMail CGI program allows remote execution of commands.</desc>
<refs>
<ref source="XF">http-cgi-formmail-exe</ref>
<ref source="BUGTRAQ">Aug02,1995</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0173" seq="1999-0173">
<status>Entry</status>
<desc>FormMail CGI program can be used by web servers other than the host server that the program resides on.</desc>
<refs>
<ref source="XF">http-cgi-formmail-use</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0174" seq="1999-0174">
<status>Entry</status>
<desc>The view-source CGI program allows remote attackers to read arbitrary files via a .. (dot dot) attack.</desc>
<refs>
<ref source="BUGTRAQ">19970208 view-source</ref>
<ref source="XF">http-cgi-viewsrc</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0175" seq="1999-0175">
<status>Entry</status>
<desc>The convert.bas program in the Novell web server allows a remote attackers to read any file on the system that is internally accessible by the web server.</desc>
<refs>
<ref source="XF">http-nov-convert</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0176" seq="1999-0176">
<status>Entry</status>
<desc>The Webgais program allows a remote user to execute arbitrary commands.</desc>
<refs>
<ref source="BUGTRAQ">Jul10,1997</ref>
<ref source="XF">http-webgais-query</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0177" seq="1999-0177">
<status>Entry</status>
<desc>The uploader program in the WebSite web server allows a remote attacker to execute arbitrary programs.</desc>
<refs>
<ref source="NTBUGTRAQ">19970904 [Alert] Website's uploader.exe (from demo) vulnerable</ref>
<ref source="NTBUGTRAQ">19970905 Re: FW: [Alert] Website's uploader.exe (from demo) vulnerable</ref>
<ref source="BUGTRAQ">19970904 [Alert] Website's uploader.exe (from demo) vulnerable</ref>
<ref source="XF">http-website-uploader</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0178" seq="1999-0178">
<status>Entry</status>
<desc>Buffer overflow in the win-c-sample program (win-c-sample.exe) in the WebSite web server 1.1e allows remote attackers to execute arbitrary code via a long query string.</desc>
<refs>
<ref source="BUGTRAQ" url="http://archives.neohapsis.com/archives/bugtraq/1997_1/0021.html">19970106 Re: signal handling</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2078">2078</ref>
<ref source="OSVDB" url="http://www.osvdb.org/8">8</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/295">http-website-winsample(295)</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0179" seq="1999-0179">
<status>Entry</status>
<desc>Windows NT crashes or locks up when a Samba client executes a &quot;cd ..&quot; command on a file share.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q140818">Q140818</ref>
<ref source="XF">nt-samba-dotdot</ref>
<ref source="XF">nt-351</ref>
<ref source="XF">nt-35</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0180" seq="1999-0180">
<status>Entry</status>
<desc>in.rshd allows users to login with a NULL username and execute commands.</desc>
<refs>
<ref source="XF">rsh-null</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0181" seq="1999-0181">
<status>Entry</status>
<desc>The wall daemon can be used for denial of service, social engineering attacks, or to execute remote commands.</desc>
<refs>
<ref source="XF">walld</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0182" seq="1999-0182">
<status>Entry</status>
<desc>Samba has a buffer overflow which allows a remote attacker to obtain root access by specifying a long password.</desc>
<refs>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/h-110.shtml">H-110</ref>
<ref source="CERT">VB-97.10.samba</ref>
<ref source="XF">nt-samba-bo</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0183" seq="1999-0183">
<status>Entry</status>
<desc>Linux implementations of TFTP would allow access to files outside the restricted directory.</desc>
<refs>
<ref source="XF">linux-tftp</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0184" seq="1999-0184">
<status>Entry</status>
<desc>When compiled with the -DALLOW_UPDATES option, bind allows dynamic updates to the DNS server, allowing for malicious modification of DNS records.</desc>
<refs>
<ref source="XF">dns-updates</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0185" seq="1999-0185">
<status>Entry</status>
<desc>In SunOS or Solaris, a remote user could connect from an FTP server's data port to an rlogin server on a host that trusts the FTP server, allowing remote command execution.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/156">00156</ref>
<ref source="XF">sun-ftpd/logind</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0186" seq="1999-0186">
<status>Candidate</status>
<phase date="20071119">Modified</phase>
<desc>In Solaris, an SNMP subagent has a default community string that allows remote attackers to execute arbitrary commands as root, or modify system parameters.</desc>
<refs>
<ref source="CONFIRM" url="http://support.novell.com/cgi-bin/search/searchtid.cgi?/10080762.htm">http://support.novell.com/cgi-bin/search/searchtid.cgi?/10080762.htm</ref>
<ref source="SUN">00178</ref>
<ref source="XF">snmp-backdoor-access</ref>
</refs>
<votes>
<accept count="2">Dik, Baker</accept>
<modify count="1">Frech</modify>
<noop count="1">Wall</noop>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Frech">Change XF:snmp-backdoor-access to XF:sol-hidden-commstr
Add ISS:Hidden Community String in SNMP Implementation</comment>
<comment voter="Christey">What is the proper level of abstraction to use here?  Should
we have a separate entry for each different default community
string?  See:
http://cve.mitre.org/Board_Sponsors/archives/msg00242.html and
http://cve.mitre.org/Board_Sponsors/archives/msg00250.html
http://cve.mitre.org/Board_Sponsors/archives/msg00251.html

Until the associated content decisions have been approved
by the Editorial Board, this candidate cannot be accepted
for inclusion in CVE.</comment>
<comment voter="Christey">ADDREF BID:177</comment>
<comment voter="Christey">ISS:19981102 Hidden community string in SNMP implementation
http://xforce.iss.net/alerts/advise11.php

Change description to include &quot;hidden&quot;</comment>
<comment voter="Christey">XF:snmp-backdoor-access is missing.</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0187" seq="1999-0187">
<status>Candidate</status>
<phase date="20050204">Modified</phase>
<desc>** REJECT **  DO NOT USE THIS CANDIDATE NUMBER.  ConsultIDs: CVE-1999-0022.  Reason: This candidate is a duplicate of CVE-1999-0022.  Notes: All CVE users should reference CVE-1999-0022 instead of this candidate.  All references and descriptions in this candidate have been removed to prevent accidental usage.</desc>
<refs>
</refs>
<votes>
<accept count="2">Hill, Northcutt</accept>
<recast count="3">Frech, Prosser, Baker</recast>
<reject count="1">Dik</reject>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Prosser">The Sun Patches in Ref roll-up fixes for an earlier BO in
rdist lookup( )(ref CERT 96.14)as well as the BO in rdist function expstr()
(ref CERT 97-23) and various vendor bulletins.  However both of these rdist
BO's affect many more OSs than just Sun, i.e., BSD/OS 2.1, DEC OSF's, AIX,
FreeBSD, SCO, SGI, etc.  Believe this falls into the SF-codebase content
decision</comment>
<comment voter="Frech">XF:rdist-bo (error msg formation)
XF:rdist-bo2 (execute code)
XF:rdist-bo3 (execute user-created code)
XF:rdist-sept97 (root from local)</comment>
<comment voter="Christey">Duplicate of CVE-1999-0022 (SUN:00179 is referenced in
CERT:CA-97.23.rdist), but as Mike and Andre noted, there
are multiple flaws here, so a RECAST may be necessary.</comment>
<comment voter="Dik">As currently phrasedm thissa duplicate of CVE-1999-0022</comment>
<comment voter="Baker">Based on our new philosophy, this should be recast/merged or re-described.</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0188" seq="1999-0188">
<status>Entry</status>
<desc>The passwd command in Solaris can be subjected to a denial of service.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/182">00182</ref>
<ref source="XF">sun-passwd-dos</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0189" seq="1999-0189">
<status>Entry</status>
<desc>Solaris rpcbind listens on a high numbered UDP port, which may not be filtered since the standard port number is 111.</desc>
<refs>
<ref source="NAI">NAI-15</ref>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/142">00142</ref>
<ref source="XF">rpc-32771</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0190" seq="1999-0190">
<status>Entry</status>
<desc>Solaris rpcbind can be exploited to overwrite arbitrary files and gain root access.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/167">00167</ref>
<ref source="XF">sun-rpcbind</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0191" seq="1999-0191">
<status>Entry</status>
<desc>IIS newdsn.exe CGI script allows remote users to overwrite files.</desc>
<refs>
<ref source="XF">http-cgi-newdsn</ref>
<ref source="OSVDB" url="http://www.osvdb.org/275">275</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0192" seq="1999-0192">
<status>Entry</status>
<desc>Buffer overflow in telnet daemon tgetent routing allows remote attackers to gain root access via the TERMCAP environmental variable.</desc>
<refs>
<ref source="SNI">SNI-20</ref>
<ref source="XF">bsd-tel-tgetent</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0193" seq="1999-0193">
<status>Candidate</status>
<phase date="19990714">Proposed</phase>
<desc>Denial of service in Ascend and 3com routers, which can be rebooted by sending a zero length TCP option.</desc>
<refs>
</refs>
<votes>
<accept count="5">Shostack, Bishop, Ozancin, Northcutt, Cole</accept>
<modify count="2">Blake, Baker</modify>
<noop count="4">Frech, Wall, Landfield, Armstrong</noop>
<reviewing count="2">Levy, Christey</reviewing>
</votes>
<comments>
<comment voter="Frech">possibly XF:ascend-kill
I can't find a reference that lists both routers in the same reference.</comment>
<comment voter="Wall">Comment:  There is a reference about the zero length TCP option in BugTraq on
Feb 5, 1999
and it mentions Cisco, but not directly Ascend or 3Com.  CIAC Advisory I-038
mentions
vulnerabilities in Ascend, but does not mention TCP.  CIAC Advisory I-052
mentions
3Com vulnerabilities, but not TCP.  Too confusing withour better references.</comment>
<comment voter="Landfield">What are the references for this ? I cannot find a means to check it out.</comment>
<comment voter="CHANGE">[Frech changed vote from REVIEWING to NOOP]</comment>
<comment voter="Frech">Cannot reconcile to our database without further references.</comment>
<comment voter="Blake">I'm with Andre.  I only remember and can find reference to the Ascend
issue.  Do we have a refernce to the 3Coms?  If not, that should be
removed from the description.</comment>
<comment voter="Baker">http://xforce.iss.net/static/614.php	Misc Defensive Info
http://www.securityfocus.com/archive/1/5682	Misc Offensive Info
http://www.securityfocus.com/archive/1/5647	Misc Defensive Info
http://www.securityfocus.com/archive/1/5640	Misc Defensive Info</comment>
<comment voter="CHANGE">[Armstrong changed vote from REVIEWING to NOOP]</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0194" seq="1999-0194">
<status>Entry</status>
<desc>Denial of service in in.comsat allows attackers to generate messages.</desc>
<refs>
<ref source="XF">comsat</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0195" seq="1999-0195">
<status>Candidate</status>
<phase date="19991130">Modified</phase>
<desc>Denial of service in RPC portmapper allows attackers to register or unregister RPC services or spoof RPC services using a spoofed source IP address such as 127.0.0.1.</desc>
<refs>
<ref source="BUGTRAQ">19990128 rpcbind: deceive, enveigle and obfuscate</ref>
</refs>
<votes>
<accept count="2">Shostack, Balinsky</accept>
<modify count="1">Frech</modify>
<noop count="3">Northcutt, Wall, Baker</noop>
<reviewing count="2">Levy, Christey</reviewing>
</votes>
<comments>
<comment voter="Frech">XF:rpcbind-spoof</comment>
<comment voter="Christey">CVE-1999-0195 = CVE-1999-0461 ?
If this is approved over CVE-1999-0461, make sure it gets
XF:pmap-sset</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0196" seq="1999-0196">
<status>Entry</status>
<desc>websendmail in Webgais 1.0 allows a remote user to access arbitrary files and execute arbitrary code via the receiver parameter ($VAR_receiver variable).</desc>
<refs>
<ref source="BUGTRAQ">19970704 Vulnerability in websendmail</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/2077">2077</ref>
<ref source="OSVDB" url="http://www.osvdb.org/237">237</ref>
<ref source="XF">http-webgais-smail</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0197" seq="1999-0197">
<status>Candidate</status>
<phase date="19990726">Proposed</phase>
<desc>finger 0@host on some systems may print information on some user accounts.</desc>
<refs>
</refs>
<votes>
<accept count="1">Baker</accept>
<modify count="2">Frech, Shostack</modify>
<reject count="1">Northcutt</reject>
</votes>
<comments>
<comment voter="Shostack">fingerd may respond to 'finger 0@host' with account info</comment>
<comment voter="Frech">Need more reference to establish this 'exposure'.</comment>
<comment voter="CHANGE">[Frech changed vote from REVIEWING to MODIFY]</comment>
<comment voter="Frech">XF:finger-unused-accounts(8378)
We're entering it into our database solely to track
competition. The only references seem to be product listings:
http://hq.mcafeeasap.com/vulnerabilities/vuln_data/1000.asp (1002
Finger 0@host check)
http://www.ipnsa.com/ipnsa_vuln.htm?step=1000 (Finger 0@host check)
http://cgi.nessus.org/plugins/dump.php3?id=10069 (Finger zero at host
feature)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0198" seq="1999-0198">
<status>Candidate</status>
<phase date="19990726">Proposed</phase>
<desc>finger .@host on some systems may print information on some user accounts.</desc>
<refs>
</refs>
<votes>
<accept count="1">Baker</accept>
<modify count="2">Frech, Shostack</modify>
<reject count="1">Northcutt</reject>
</votes>
<comments>
<comment voter="Shostack">as above</comment>
<comment voter="Frech">Need more reference to establish this 'exposure'.</comment>
<comment voter="CHANGE">[Frech changed vote from REVIEWING to MODIFY]</comment>
<comment voter="Frech">XF:finger-unused-accounts(8378)
We're entering it into our database solely to track
competition. The only references seem to be product listings:
http://hq.mcafeeasap.com/vulnerabilities/vuln_data/1000.asp (1004
Finger .@target-host check)
http://www.ipnsa.com/ipnsa_vuln.htm?step=1000 (Finger .@target-host
check )
http://cgi.nessus.org/plugins/dump.php3?id=10072 (Finger dot at host
feature)</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0200" seq="1999-0200">
<status>Candidate</status>
<phase date="19991130">Modified</phase>
<desc>Windows NT FTP server (WFTP) with the guest account enabled without a password allows an attacker to log into the FTP server using any username and password.</desc>
<refs>
<ref source="MSKB">Q137853</ref>
</refs>
<votes>
<accept count="1">Baker</accept>
<modify count="2">Frech, Shostack</modify>
<noop count="2">Northcutt, Wall</noop>
<reject count="1">Christey</reject>
<reviewing count="1">Levy</reviewing>
</votes>
<comments>
<comment voter="Shostack">WFTP is not sufficient; is this wu-, ws-, war-, or another?</comment>
<comment voter="Frech">Other have mentioned this before, but it may be WU-FTP.
POSSIBLY XF:ftp-exec; does this have to do with the Site Exec allowing root
access without anon FTP or a regular account?
POSSIBLY XF:wu-ftpd-exec;same as above conditions, but instead from a
non-anon FTP account and gain root privs.</comment>
<comment voter="Christey">added MSKB reference</comment>
<comment voter="CHANGE">[Christey changed vote from REVOTE to REJECT]</comment>
<comment voter="Christey">The MSKB article may have confused things even more.  There
were reports of problems in a Windows-based FTP server called
WFTP (http://www.wftpd.com/) that is not a Microsft FTP
server.  It's best to just kill this candidate where it
stands and start fresh.</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0201" seq="1999-0201">
<status>Entry</status>
<desc>A quote cwd command on FTP servers can reveal the full path of the home directory of the &quot;ftp&quot; user.</desc>
<refs>
<ref source="XF">ftp-home</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0202" seq="1999-0202">
<status>Entry</status>
<desc>The GNU tar command, when used in FTP sessions, may allow an attacker to execute arbitrary commands.</desc>
<refs>
<ref source="XF">ftp-exectar</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0203" seq="1999-0203">
<status>Entry</status>
<desc>In Sendmail, attackers can gain root privileges via SMTP by specifying an improper &quot;mail from&quot; address and an invalid &quot;rcpt to&quot; address that would cause the mail to bounce to a program.</desc>
<refs>
<ref source="CERT">CA-95.08</ref>
<ref source="CIAC">E-03</ref>
<ref source="XF">smtp-sendmail-version5</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0204" seq="1999-0204">
<status>Entry</status>
<desc>Sendmail 8.6.9 allows remote attackers to execute root commands, using ident.</desc>
<refs>
<ref source="XF">ident-bo</ref>
<ref source="CIAC">F-13</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0205" seq="1999-0205">
<status>Candidate</status>
<phase date="19990925">Modified</phase>
<desc>Denial of service in Sendmail 8.6.11 and 8.6.12.</desc>
<refs>
<ref source="BUGTRAQ">19990708 SM 8.6.12</ref>
</refs>
<votes>
<accept count="2">Hill, Northcutt</accept>
<modify count="2">Frech, Prosser</modify>
<noop count="1">Baker</noop>
<reviewing count="2">Ozancin, Christey</reviewing>
</votes>
<comments>
<comment voter="Frech">XF:sendmail-alias-dos</comment>
<comment voter="Prosser">additional source
Bugtraq
&quot;Re:  SM 8.6.12&quot;
http://www.securityfocus.com</comment>
<comment voter="Christey">The Bugtraq thread does not provide any proof, including a
comment by Eric Allman that he hadn't been provided any
details either.

See http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=1995-07-8&amp;thread=199507131402.KAA02492@bedbugs.net.ohio-state.edu
for the thread.</comment>
<comment voter="Christey">Change Bugtraq reference date to 19950708.</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0206" seq="1999-0206">
<status>Entry</status>
<desc>MIME buffer overflow in Sendmail 8.8.0 and 8.8.1 gives root access.</desc>
<refs>
<ref source="XF">sendmail-mime-bo</ref>
<ref source="AUSCERT">AA-96.06a</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0207" seq="1999-0207">
<status>Entry</status>
<desc>Remote attacker can execute commands through Majordomo using the Reply-To field and a &quot;lists&quot; command.</desc>
<refs>
<ref source="XF">majordomo-exe</ref>
<ref source="CERT">CA-94.11.majordomo.vulnerabilities</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0208" seq="1999-0208">
<status>Entry</status>
<desc>rpc.ypupdated (NIS) allows remote users to execute arbitrary commands.</desc>
<refs>
<ref source="XF">rpc-update</ref>
<ref source="CERT">CA-95.17.rpc.ypupdated.vul</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0209" seq="1999-0209">
<status>Entry</status>
<desc>The SunView (SunTools) selection_svc facility allows remote users to read files.</desc>
<refs>
<ref source="CERT">CA-90.05.sunselection.vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/8">8</ref>
<ref source="XF">selsvc</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0210" seq="1999-0210">
<status>Entry</status>
<desc>Automount daemon automountd allows local or remote users to gain privileges via shell metacharacters.</desc>
<refs>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=88053459921223&amp;w=2">19971126 Solaris 2.5.1 automountd exploit (fwd)</ref>
<ref source="BUGTRAQ" url="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=91547759121289&amp;w=2">19990103 SUN almost has a clue! (automountd)</ref>
<ref source="HP" url="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9910-104">HPSBUX9910-104</ref>
<ref source="CERT" url="http://www.cert.org/advisories/CA-99-05-statd-automountd.html">CA-99-05</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/235">235</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0211" seq="1999-0211">
<status>Entry</status>
<desc>Extra long export lists over 256 characters in some mount daemons allows NFS directories to be mounted by anyone.</desc>
<refs>
<ref source="CERT">CA-94.02.REVISED.SunOS.rpc.mountd.vulnerability</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/24">24</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0212" seq="1999-0212">
<status>Entry</status>
<desc>Solaris rpc.mountd generates error messages that allow a remote attacker to determine what files are on the server.</desc>
<refs>
<ref source="SUN" url="http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/168">00168</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/i-048.shtml">I-048</ref>
<ref source="XF">sun-mountd</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0213" seq="1999-0213">
<status>Candidate</status>
<phase date="20001009">Modified</phase>
<desc>libnsl in Solaris allowed an attacker to perform a denial of service of rpcbind.</desc>
<refs>
<ref source="XF">sun-libnsl</ref>
<ref source="SUNBUG">4305859</ref>
</refs>
<votes>
<accept count="6">Dik, Ozancin, Hill, Blake, Landfield, Cole</accept>
<modify count="3">Frech, Levy, Baker</modify>
<noop count="4">Bishop, Meunier, Wall, Armstrong</noop>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Frech">XF:sun-libnsl</comment>
<comment voter="Dik">Sun bug #4305859</comment>
<comment voter="Baker">http://xforce.iss.net/static/1204.php	Misc Defensive Info
http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&amp;doc=secbull/172&amp;type=0&amp;nav=sec.sba	Vendor Info
http://www-1.ibm.com/services/continuity/recover1.nsf/advisories/A1050E354364BF498525680F0077E414/$file/ERS-OAR-E01-1998_074_1.txt	Vendor Info
http://www.securityfocus.com/archive/1/9749	Misc Defensive Info</comment>
<comment voter="Christey">I don't think this is the bug that everyone thinks it is.
This candidate came from CyberCop Scanner 2.4/2.5, which
only reports this as a DoS problem.  If SUN:00172 is an
advisory for this, then it may be a duplicate of
CVE-1999-0055.  There appears to be overlap with other
references as well.  HOWEVER, this particular one deals with a
DoS in rpcbind - which isn't mentioned in the sources for
CVE-1999-0055.</comment>
<comment voter="Levy">BID 148</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0214" seq="1999-0214">
<status>Entry</status>
<desc>Denial of service by sending forged ICMP unreachable packets.</desc>
<refs>
<ref source="XF">icmp-unreachable</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0215" seq="1999-0215">
<status>Entry</status>
<desc>Routed allows attackers to append data to files.</desc>
<refs>
<ref source="SGI" url="ftp://patches.sgi.com/support/free/security/advisories/19981004-01-PX">19981004-01-PX</ref>
<ref source="CIAC" url="http://www.ciac.org/ciac/bulletins/j-012.shtml">J-012</ref>
<ref source="XF">ripapp</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0216" seq="1999-0216">
<status>Candidate</status>
<phase date="19991203">Modified</phase>
<desc>Denial of service of inetd on Linux through SYN and RST packets.</desc>
<refs>
<ref source="BUGTRAQ">19971130 Linux inetd..</ref>
<ref source="XF">linux-inetd-dos</ref>
<ref source="HP">HPSBUX9803-077</ref>
<ref source="XF">hp-inetd</ref>
</refs>
<votes>
<accept count="1">Hill</accept>
<modify count="2">Frech, Baker</modify>
<recast count="1">Meunier</recast>
</votes>
<comments>
<comment voter="Meunier">The location of the vulnerability, whether in the Linux kernel or the
application, is debatable.  Any program making the same (reasonnable)
assumption is vulnerable, i.e., implements the same vulnerability:
&quot;Assumption that TCP-three-way handshake is complete after calling Linux
kernel function accept(), which returns socket after getting SYN.   Result
is process death by SIGPIPE&quot;
Moreover, whether it results in DOS (to third parties) depends on the
process that made the assumption.
I think that the present entry should be split, one entry for every
application that implements the vulnerability (really describing threat
instances, which is what other people think about when we talk about
vulnerabilities), and one entry for the Linux kernel that allows the
vulnerability to happen.</comment>
<comment voter="Frech">XF:hp-inetd
XF:linux-inetd-dos</comment>
<comment voter="Baker">Since we have an hpux bulletin, the description should not specifically say Linux, should it?  It applies to mulitple OS and should be likely either modified, or in extreme case, recast</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0217" seq="1999-0217">
<status>Entry</status>
<desc>Malicious option settings in UDP packets could force a reboot in SunOS 4.1.3 systems.</desc>
<refs>
<ref source="XF">udp-bomb</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0218" seq="1999-0218">
<status>Entry</status>
<desc>Livingston portmaster machines could be rebooted via a series of commands.</desc>
<refs>
<ref source="XF">portmaster-reboot</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0219" seq="1999-0219">
<status>Entry</status>
<desc>Buffer overflow in FTP Serv-U 2.5 allows remote authenticated users to cause a denial of service (crash) via a long (1) CWD or (2) LS (list) command.</desc>
<refs>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92574916930144&amp;w=2">19990503 Buffer overflows in FTP Serv-U 2.5</ref>
<ref source="NTBUGTRAQ" url="http://marc.theaimsgroup.com/?l=ntbugtraq&amp;m=92582581330282&amp;w=2">19990504 Re: Buffer overflows in FTP Serv-U 2.5</ref>
<ref source="BUGTRAQ">19990909 Exploit: Serv-U Ver2.5 FTPd Win9x/NT</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/269">269</ref>
<ref source="XF" url="http://xforce.iss.net/xforce/xfdb/205">ftp-servu(205)</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0220" seq="1999-0220">
<status>Candidate</status>
<phase date="19990728">Proposed</phase>
<desc>Attackers can do a denial of service of IRC by crashing the server.</desc>
<refs>
</refs>
<votes>
<noop count="2">Northcutt, Baker</noop>
<reject count="2">Frech, Christey</reject>
</votes>
<comments>
<comment voter="Frech">Would reconsider if any references were available.</comment>
<comment voter="Christey">No references available, combined with extremely vague
description, equals REJECT.</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0221" seq="1999-0221">
<status>Entry</status>
<desc>Denial of service of Ascend routers through port 150 (remote administration).</desc>
<refs>
<ref source="XF">ascend-150-kill</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0222" seq="1999-0222">
<status>Candidate</status>
<phase date="19990714">Proposed</phase>
<desc>Denial of service in Cisco IOS web server allows attackers to reboot the router using a long URL.</desc>
<refs>
</refs>
<votes>
<accept count="1">Baker</accept>
<modify count="3">Frech, Shostack, Levy</modify>
<noop count="3">Balinsky, Northcutt, Wall</noop>
<recast count="1">Ziese</recast>
<reject count="1">Christey</reject>
</votes>
<comments>
<comment voter="Shostack">I follow cisco announcements and problems pretty closely, and haven't
seen this.  Source?</comment>
<comment voter="Frech">XF:cisco-web-crash</comment>
<comment voter="Christey">XF:cisco-web-crash has no additional references.  I can't find
any references in Bugtraq or Cisco either.  This bug is
supposedly tested by at least one security product, but that
product's database doesn't have any references either.  So
a question becomes, how did it make it into at least two
security companies' databases?</comment>
<comment voter="Levy">BUGTGRAQ: http://www.securityfocus.com/archive/1/60159
BID 1154</comment>
<comment voter="Ziese">The vulnerability is addressed by a vendor acknowledgement.  This one, if
recast to reflect that &quot;...after using a long url...&quot; should be replaced
with
&quot;...A defect in multiple releases of Cisco IOS software will cause a Cisco
router or switch to halt and reload if the IOS HTTP service is enabled,
browsing to &quot;http://router-ip/anytext?/&quot; is attempted, and the enable
password is supplied when requested. This defect can be exploited to produce
a denial of service (DoS) attack.&quot;
Then I can accept this and mark it as &quot;Verfied by my Company&quot;.  If it can't
be recast because this (long uri) is diffferent then our release (special
url construction).</comment>
<comment voter="CHANGE">[Christey changed vote from REVIEWING to REJECT]</comment>
<comment voter="Christey">Elias Levy's suggested reference is CVE-2000-0380.
I don't think that Kevin's description is really addressing
this either.  The lack of references and a specific
description make this candidate unusable, so it should be
rejected.</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0223" seq="1999-0223">
<status>Entry</status>
<desc>Solaris syslogd crashes when receiving a message from a host that doesn't have an inverse DNS entry.</desc>
<refs>
<ref source="BUGTRAQ">19961109 Syslogd and Solaris 2.4</ref>
<ref source="SUNBUG">1249320</ref>
<ref source="CONFIRM" url="http://sunsolve.Sun.COM/pub-cgi/retrieve.pl?patchid=103291&amp;collection=fpatches">http://sunsolve.Sun.COM/pub-cgi/retrieve.pl?patchid=103291&amp;collection=fpatches</ref>
<ref source="XF">sol-syslogd-crash</ref>
<ref source="BID" url="http://www.securityfocus.com/bid/1878">1878</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0224" seq="1999-0224">
<status>Entry</status>
<desc>Denial of service in Windows NT messenger service through a long username.</desc>
<refs>
<ref source="XF">nt-messenger</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0225" seq="1999-0225">
<status>Entry</status>
<desc>Windows NT 4.0 allows remote attackers to cause a denial of service via a malformed SMB logon request in which the actual data size does not match the specified size.</desc>
<refs>
<ref source="NAI" url="http://www.nai.com/nai_labs/asp_set/advisory/25_windows_nt_dos_adv.asp">19980214 Windows NT Logon Denial of Service</ref>
<ref source="MSKB" url="http://www.microsoft.com/technet/support/kb.asp?ID=180963">Q180963</ref>
<ref source="XF">nt-logondos</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0226" seq="1999-0226">
<status>Candidate</status>
<phase date="19990728">Proposed</phase>
<desc>Windows NT TCP/IP processes fragmented IP packets improperly, causing a denial of service.</desc>
<refs>
</refs>
<votes>
<accept count="1">Northcutt</accept>
<modify count="1">Frech</modify>
<noop count="1">Baker</noop>
<reject count="1">Christey</reject>
</votes>
<comments>
<comment voter="Christey">Too general, and no references.</comment>
<comment voter="Frech">XF:nt-frag(528)
See reference from BugTraq Mailing List, &quot;A New Fragmentation Attack&quot; at
http://www.securityfocus.com/templates/archive.pike?list=1&amp;date=1997-07-8&amp;ms
g=Pine.SUN.3.94.970710054440.11707A-100000@dfw.dfw.net</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0227" seq="1999-0227">
<status>Entry</status>
<desc>Access violation in LSASS.EXE (LSA/LSARPC) program in Windows NT allows a denial of service.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q154087">Q154087</ref>
<ref source="XF">nt-lsass-crash</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0228" seq="1999-0228">
<status>Entry</status>
<desc>Denial of service in RPCSS.EXE program (RPC Locator) in Windows NT.</desc>
<refs>
<ref source="XF">nt-rpc-ver</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q162567">Q162567</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0229" seq="1999-0229">
<status>Candidate</status>
<phase date="19991228">Modified</phase>
<desc>Denial of service in Windows NT IIS server using ..\..</desc>
<refs>
<ref source="MSKB">Q115052</ref>
</refs>
<votes>
<accept count="2">Shostack, Baker</accept>
<modify count="2">Frech, Wall</modify>
<noop count="1">Northcutt</noop>
<reject count="1">Christey</reject>
<reviewing count="1">Levy</reviewing>
</votes>
<comments>
<comment voter="Wall">Denial of service in Windows NT IIS Server 1.0 using ..\...
Source: Microsoft Knowledge Base Article Q115052 - IIS Server.</comment>
<comment voter="Frech">XF:http-dotdot (not necessarily IIS?)</comment>
<comment voter="Christey">DELREF XF:http-dotdot - it deals with a read/access dot dot
problem.</comment>
<comment voter="Christey">This actually looks like XF:iis-dot-dot-crash(1638)
http://xforce.iss.net/static/1638.php
If so, include the version number (2.0)
</comment>
<comment voter="CHANGE">[Christey changed vote from REVOTE to REJECT]</comment>
<comment voter="Christey">Bill Wall intended to suggest Q155052, but the affected
IIS version there is 1.0; the effect is to read files,
so this sounds like a directory traversal problem,
instead of an inability to process certain strings.

As a result, this candidate is too general, since it could
apply to 2 different problems, so it should be REJECTed.</comment>
<comment voter="Christey">Consider adding BID:2218</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0230" seq="1999-0230">
<status>Entry</status>
<desc>Buffer overflow in Cisco 7xx routers through the telnet service.</desc>
<refs>
<ref source="CISCO">http://www.cisco.com/warp/public/770/pwbuf-pub.shtml</ref>
<ref source="OSVDB" url="http://www.osvdb.org/1102">1102</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0231" seq="1999-0231">
<status>Candidate</status>
<phase date="19991207">Modified</phase>
<desc>Buffer overflow in IP-Switch IMail and Seattle Labs Slmail 2.6 packages using a long VRFY command, causing a denial of service and possibly remote access.</desc>
<refs>
<ref source="BUGTRAQ">19990317 Re: SLMail 2.6 DoS - Imail also</ref>
</refs>
<votes>
<accept count="2">Levy, Baker</accept>
<noop count="3">Christey, Northcutt, Landfield</noop>
<recast count="1">Frech</recast>
<reviewing count="1">Ozancin</reviewing>
</votes>
<comments>
<comment voter="Frech">XF:slmail-vrfyexpn-overflow (for Slmail v3.2 and below)
XF:smtp-vrfy-bo (many mail packages)</comment>
<comment voter="Northcutt">(There is no way I will have access to these systems)</comment>
<comment voter="Christey">Some sources report that VRFY and EXPN are both affected.</comment>
</comments>
</item>

<item type="CAN" name="CVE-1999-0232" seq="1999-0232">
<status>Candidate</status>
<phase date="19991220">Modified</phase>
<desc>Buffer overflow in NCSA WebServer (version 1.5c) gives remote access.</desc>
<refs>
</refs>
<votes>
<accept count="2">Hill, Northcutt</accept>
<modify count="1">Frech</modify>
<noop count="1">Prosser</noop>
<reject count="1">Baker</reject>
<reviewing count="1">Christey</reviewing>
</votes>
<comments>
<comment voter="Frech">Unable to provide a match due to vague/insufficient description/references.
Possible matches are:
XF:ftp-ncsa (probably not, considering you've mentioned the webserver.)
XF:http-ncsa-longurl (highest probability)</comment>
<comment voter="Christey">CVE-1999-0235 is the one associated with XF:http-ncsa-longurl
More research is necessary for this one.</comment>
<comment voter="Baker">Since this has no references at all, and is vague and we have a
CAN for the most likely issue, we should kill this one</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0233" seq="1999-0233">
<status>Entry</status>
<desc>IIS 1.0 allows users to execute arbitrary commands using .bat or .cmd files.</desc>
<refs>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q148188">Q148188</ref>
<ref source="MSKB" url="http://support.microsoft.com/default.aspx?scid=kb;[LN];Q155056">Q155056</ref>
<ref source="XF">http-iis-cmd</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0234" seq="1999-0234">
<status>Entry</status>
<desc>Bash treats any character with a value of 255 as a command separator.</desc>
<refs>
<ref source="XF">bash-cmd</ref>
<ref source="CERT">CA-96.22.bash_vuls</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0235" seq="1999-0235">
<status>Candidate</status>
<phase date="19991220">Modified</phase>
<desc>Buffer overflow in NCSA WebServer (1.4.1 and below) gives remote access.</desc>
<refs>
<ref source="CERT">CA-95:04</ref>
<ref source="CIAC">F-11</ref>
</refs>
<votes>
<accept count="3">Hill, Prosser, Northcutt</accept>
<modify count="1">Frech</modify>
<reject count="2">Christey, Baker</reject>
</votes>
<comments>
<comment voter="Frech">XF:http-ncsa-longurl</comment>
<comment voter="Christey">CVE-1999-0235 has the same ref's as CVE-1999-0267</comment>
<comment voter="Baker">Not to mention, the X-force listings of http-ncsa-longurl and http-port both
refer to the same problem.  This should be rejected as 1999-0267 is the same problem.</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0236" seq="1999-0236">
<status>Entry</status>
<desc>ScriptAlias directory in NCSA and Apache httpd allowed attackers to read CGI programs.</desc>
<refs>
<ref source="XF">http-scriptalias</ref>
</refs>
</item>

<item type="CVE" name="CVE-1999-0237" seq="1999-0237">
<status>Entry</status>
<desc>Remote execution of arbitrary commands through Guestbook CGI program.</desc>
<refs>
<ref source="XF">http-cgi-guestbook</ref>
<ref source="CERT">VB-97.02</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0238" seq="1999-0238">
<status>Candidate</status>
<phase date="19990623">Proposed</phase>
<desc>php.cgi allows attackers to read any file on the system.</desc>
<refs>
<ref source="XF">http-cgi-phpfileread</ref>
</refs>
<votes>
<accept count="5">Frech, Collins, Prosser, Northcutt, Baker</accept>
<noop count="1">Christey</noop>
</votes>
<comments>
<comment voter="Prosser">additional source
AUSCERT External Security Bulletin ESB-97.047
http://www.auscert.org.au</comment>
<comment voter="Christey">ADDREF BUGTRAQ:19970416 Update on PHP/FI hole
URL:http://www.dataguard.no/bugtraq/1997_2/0069.html
The attacker specifies the filename as an argument to the
program.
Add &quot;PHP/FI&quot; to description to facilitate search.
AUSCERT URL is ftp://ftp.auscert.org.au/pub/auscert/ESB/ESB-97.047</comment>
<comment voter="Christey">Consider adding BID:2250</comment>
</comments>
</item>

<item type="CVE" name="CVE-1999-0239" seq="1999-0239">
<status>Entry</status>
<desc>Netscape FastTrack Web server lists files when a lowercase &quot;get&quot; command is used instead of an uppercase GET.</desc>
<refs>
<ref source="XF">fastrack-get-directory-list</ref>
<ref source="OSVDB" url="http://www.osvdb.org/122">122</ref>
</refs>
</item>

<item type="CAN" name="CVE-1999-0240" seq="1999-0240">
<status>Candidate</status>
<phase date="19990728">Proposed</phase>
<desc>Some filters or firewalls allow fragmented SYN packets with IP reserved bits in violation of their implemented policy.</desc>
<refs>
</refs>
<votes>
<accept count="1">Northcutt</accept>
<noop count="1">Baker</noop>
<rej