Bugtraq: by date

296 messages starting Sep 10 98 and ending Nov 30 98
Date index | Thread index | Author index


Thursday, 10 September

[Linux] klogd 1.3-22 buffer overflow Michal Zalewski

Saturday, 12 September

Re: [Linux] klogd 1.3-22 buffer overflow Michal Zalewski

Friday, 30 October

Re: Javascript bug in Netscape Communicator 4.5 Jim Reavis
Re: navigator lost (settings) Russell Van Tassell
homemade fix for recent bash buf OF Andrey Alekseyev
Re: Printer Sharing and M1CR0S0FT Windows98 Ryan Russell
Re: Bug in Solaris 2.6 ??? donald.pandori () PS GE COM
Pointcast and destination IP 1.1.1.1 Jean Chouanard
Re: Summary of Printer Sharing and M1CR0S0FT Windows98 Robert Richard George 'reptile' Wal
Re: Watchguard Firewall internal D.O.S WatchGuard Rapid Response
Re: Sendmail, lynx, Netscape, sshd, Linux kernel (twice) Wietse Venema

Saturday, 31 October

SSH Communications page on rootshell.com morex .-

Sunday, 01 November

mpg123-0.59k bufferoverflow. Joel Eriksson
Quake problem? mj () SMACKDADDY NET
Re: possible quake problem mj () SMACKDADDY NET
ssh-1.2.26 patch for log_msg() overflow Dug Song
SSHD Exploit Justin Foutts
Re: ssh-1.2.26 patch joshua grubman
lightbar vulnerability Config Urator
ssh-1.2.26 buffer overflow patch Andy Church

Monday, 02 November

No vulnerability known in SSH-1.2.26 Tatu Ylonen
Some revelations about ssh and stackpatch M.C.Mar
another /usr/dt/bin/dtappgather feature! Andrea Costantino
APC PowerNet SNMP vulnerability Tim Yocum
Re: Sendmail, lynx, Netscape, sshd, Linux kernel (twice) Pavel Kankovsky
Re: WatchGuard Firewall internal D.O.S Karl Stevens
X11 cookie hijacker Pavel Kankovsky
ISS Security Advisory: Hidden community string in SNMP X-Force
ISS Security Advisory: Hidden SNMP community in HP OpenView X-Force
ISS Security Advisory: BMC PATROL File Creation Vulnerability X-Force
10th anniversary of the Internet Worm Gregory Newby
head -c 32 /dev/socksys caused panic? A Fortunate K-9
Re: X11 cookie hijacker David Dawes

Tuesday, 03 November

Re. ssh-1.2.26 patch for log_msg() overflow (scp fix) Andrew Daviel
Sendmail/Qmail DoS Salvatore Sanfilippo
Re: [L0pht Advisory] MacOS - FWB passwords easily bypassed Bill Genzoli
[rootshell] Security Bulletin #25 Aleph One
Bug (Quirk?) w/Novell BorderManager Robert MACDONALD
Re: Sendmail, lynx, Netscape, sshd, Linux kernel (twice) Alan Cox
Re: Summary of Printer Sharing and M1CR0S0FT Windows98 Paul Leach
Re: Some revelations about ssh and stackpatch Pavel Kankovsky
Re: Some revelations about ssh and stackpatch Alan J Rosenthal
Re: Pointcast and destination IP 1.1.1.1 pedward () WEBCOM COM
Re: Quake problem? Matt Watson
Re: head -c 32 /dev/socksys caused panic? Brandon S. Allbery
Re: WatchGuard Firewall internal D.O.S B. James Phillippe
Re: X11 cookie hijacker Alan Cox
Re: 10th anniversary of the Internet Worm Perry E. Metzger
Form insecurity in Netscape kelani
Re: head -c 32 /dev/socksys caused panic? Alan Cox
Re: ssh-1.2.26 buffer overflow patch Michael Jennings
Re: ssh-1.2.26 buffer overflow patch Andy Church
Re: 10th anniversary of the Internet Worm Rich Kulawiec

Wednesday, 04 November

Re: X11 cookie hijacker Willy TARREAU
Re: Bug in Solaris 2.6 ??? Darren J Moffat - Enterprise Services OS Product Support Group
Re: X11 cookie hijacker Casper Dik
Re: lightbar vulnerability Aaron Bornstein
Re: another /usr/dt/bin/dtappgather feature! Casper Dik
Re: navigator lost (settings) A Mennucc1
Re: ssh-1.2.26 buffer overflow patch Joel Eriksson
quakeworld/win32 DoS Paul Boehm
Re: X11 cookie hijacker der Mouse
Re: SSHD Exploit Aleph One
Communicator 4.5 stores EVERY mail-password in preferences.js Holger van Lengerich
Re: Some revelations about ssh and stackpatch Andy Church
Re: Quake problem? Ambrose Feinstein
Re: another /usr/dt/bin/dtappgather feature! Luca Berra
Re: Form insecurity in Netscape Mark R. Bowyer - Sun UK - Sun Developer Relations
Re: SSH Communications page on rootshell.com Mitch Vincent
FreeBSD Security Advisory: FreeBSD-SA-98:08.fragment Aleph One
Re: Form insecurity in Netscape Andy Avery
FoolProof for PC Exploit Krish Jagannathan
Regarding the reported DOS against the internal interface of a WatchGuard Rapid Response
IE 4.x does not appear to save custom security settings John Schultz
Re: Quake problem? Mark Santaniello
Re: Communicator 4.5 stores EVERY mail-password in preferences.js HD Moore
Re: Communicator 4.5 stores EVERY mail-password in preferences.js HD Moore
Re: ISS Security Advisory: Hidden community string in SNMP Jean Chouanard
security patch for ssh-1.2.26 kerberos code Tatu Ylonen
Possible mail spool problem signal
Re: another /usr/dt/bin/dtappgather feature! Ben Collins
Re: X11 cookie hijacker David Dawes
xlock mishandles malformed .signature/.plan Aaron Campbell

Thursday, 05 November

Re: X11 cookie hijacker Olaf Kirch
Secure-linux patch Ernst Jan Plugge
Re: quakeworld/win32 DoS Alexander Sanda
Re: another /usr/dt/bin/dtappgather feature! Mike Iglesias
Cisco security notice: Cisco IOS DFS Access List Leakage security-alert () cisco com
Re: Communicator 4.5 stores EVERY mail-password in preferences.js Pierre Belanger
Re: ISS Security Advisory: Hidden community string in SNMP Davin Milun
Re: ISS Security Advisory: Hidden community string in SNMP Roland Grefer
Re: another /usr/dt/bin/dtappgather feature! Scott Cromar
Re: Possible mail spool problem CyberPsychotic
Re: Possible mail spool problem Conrad Juleff
various *lame* DoS attacks Conrad Juleff

Friday, 06 November

Re: another /usr/dt/bin/dtappgather feature! Paolo Amendola
Making xlock setuid root Stefan Rompf
Which crypto algorithm? was: Communicator 4.5 stores EVERY Luis Saiz
Re: xlock mishandles malformed .signature/.plan Jochen Thomas Bauer
Re: another /usr/dt/bin/dtappgather feature! J.A. Gutierrez
Re: SSHD Exploit Crispin Cowan
[Fwd: NOTE: Solaris 7 gotcha for some ultras] Dave Zwieback
Re: Which crypto algorithm? was: Communicator 4.5 stores Thievco

Saturday, 07 November

NS-C4.5 & Mail-Passwords Holger van Lengerich
Re: xlock mishandles malformed .signature/.plan Aaron Campbell
Re: various *lame* DoS attacks puppet

Sunday, 08 November

XFree86 3.3.2's setup tool /tmp race Adrian Voinea
shadow problems. twiztah
tcpd -DPARANOID doesn't work, and never did D. J. Bernstein

Monday, 09 November

Re: xlock mishandles malformed .signature/.plan tschweik () FIDUCIA DE
Major Explorer 4 java security hole! Aleph One
WWWBoard Vulnerability Samuel Sparling
Re: XFree86 3.3.2's setup tool /tmp race Steve Bellovin
Buffer overflow in Xprt Paolo Molaro
Re: Sendmail, lynx, Netscape, sshd, Linux kernel (twice) Wietse Venema
Re: another /usr/dt/bin/dtappgather feature! Casper Dik
Sun Security Bulletin #00178 joshua grubman
Re: FoolProof for PC Exploit Erik Soroka
Re: FoolProof for PC Exploit axon
Vulnerabilities with Swish Job de Haas
Re: FoolProof for PC Exploit Darren Rogers
Re: FoolProof for PC Exploit The Tree of Life
Re: tcpd -DPARANOID doesn't work, and never did Wietse Venema
Re: tcpd -DPARANOID doesn't work, and never did Warner Losh
Re: tcpd -DPARANOID doesn't work, and never did Dave Barr
Several new CGI vulnerabilities xnec
Re: tcpd -DPARANOID doesn't work, and never did Wietse Venema
Re: tcpd -DPARANOID doesn't work, and never did D. J. Bernstein
Re: Several new CGI vulnerabilities Randal Schwartz
Re: tcpd -DPARANOID doesn't work, and never did Peter Wemm
Re: FoolProof for PC Exploit William Tiemann
Re: tcpd -DPARANOID doesn't work, and never did Jim Dennis
Re: tcpd -DPARANOID doesn't work, and never did Wietse Venema

Tuesday, 10 November

Re: Several new CGI vulnerabilities Karl Hanmore
Re: tcpd -DPARANOID doesn't work, and never did Darren Reed
Re: WWWBoard Vulnerability Spartak Radchenko
Re: Several new CGI vulnerabilities Gus
Vulnerabilities with Swish Jochen Thomas Bauer
Re: tcpd -DPARANOID doesn't work, and never did Chip Christian
Re: tcpd -DPARANOID doesn't work, and never did Greg A. Woods
world-readable shadow backups in SuSe 5.2 HD Moore
Re: Several new CGI vulnerabilities Lincoln Stein
Re: Sendmail, lynx, Netscape, sshd, Linux kernel (twice) Andi Kleen
Re: tcpd -DPARANOID doesn't work, and never did Wietse Venema
Re: FoolProof for PC Exploit pcsupport () smartstuff com
Re: tcpd -DPARANOID doesn't work, and never did D. J. Bernstein
catdoc-0.90 buffer overruns Duncan Simpson
Xinetd /tmp race? Balazs Nagy
Re: WWWBoard Vulnerability Samuel Sparling

Wednesday, 11 November

Re: xlock mishandles malformed .signature/.plan tschweik () FIDUCIA DE
Re: [Fwd: NOTE: Solaris 7 gotcha for some ultras] Paul Murphy
Re: klogd 1.3-22 buffer overflow Neil Bright
NT DNS hacked ... ? Sam R. Akhtar
Re: Check system calls (was Re: Several new CGI vulnerabilities) Chip Salzenberg
Administrivia Aleph One
mSQL dummies Peter Boutzev
Re: world-readable shadow backups in SuSe 5.2 Erik
SCO World Script Vulnerabilities Ben Laurie
WARNING: Another ICQ IP address vulnerability Mnemonix
Citadel security exploits? Stout, Bill
Re: [Linux] klogd 1.3-22 buffer overflow Cory Visi
Re: Xinetd /tmp race? Wayne Schroeder
Re: [Fwd: NOTE: Solaris 7 gotcha for some ultras] Alan Cox
Re: Xinetd /tmp race? Glynn Clements
Re: world-readable shadow backups in SuSe 5.2 Andrew Pitman
Re: tcpd -DPARANOID doesn't work, and never did Wietse Venema
Re: world-readable shadow backups in SuSe 5.2 xnec
Re: klogd 1.3-22 buffer overflow Peter van Dijk
Re: Sendmail, lynx, Netscape, sshd, Linux kernel (twice) David S. Miller

Thursday, 12 November

Bootpd 2.4.3 tmp race Marcelo Tosatti
Re: Xinetd /tmp race? Jesús Cea Avión
Gandalf xpresstack bug Steve Kosciolek
Re: Several new CGI vulnerabilities Lincoln Stein
Re: NT DNS hacked ... ? Fowler, James
Re: NT DNS hacked ... ? John Fraizer
Re: Xinetd /tmp race? Glynn Clements
Re: world-readable shadow backups in SuSe 5.2 Roman Drahtmueller
Sendmail DoS (was: Re: various *lame* DoS attacks) net.ikon
Re: SCO World Script Vulnerabilities Joe
Re: catdoc-0.90 buffer overruns Kragen
[Fwd: Strange auth bug] Netscape Communicator 4.0x? Guille
More msql... Peter Boutzev

Friday, 13 November

Re: Xinetd /tmp race? Marc Heuse
Re: [Fwd: NOTE: Solaris 7 gotcha for some ultras] Solar Designer
Security hole found in junkbuster program. (fwd) condor () SEKURE ORG
Re: [Fwd: NOTE: Solaris 7 gotcha for some ultras] Tabor J. Wells
Re: NT DNS hacked ... ? Marc Slemko
Re: Old IRC Client bug Re-Applied knarph () LINUX SAVANT-CORP COM
Re: SCO World Script Vulnerabilities Ben Laurie
Re: Gandalf xpresstack bug Eric Kimminau
Re: Old IRC Client bug Re-Applied System Administrator
Re: Xinetd /tmp race? stanislav shalunov
Re: Bootpd 2.4.3 tmp race Pavel Kankovsky
Re: SCO World Script Vulnerabilities //Stany
Re: Xinetd /tmp race? Pavel Kankovsky
Re: NT DNS hacked ... ? bobk
(spoofed) RPC portmapper set/unset ga
Re: NT DNS hacked ... ? Don Lewis

Saturday, 14 November

Re: [Fwd: NOTE: Solaris 7 gotcha for some ultras] Casper Dik
Re: Xinetd /tmp race? Casper Dik
Re: NT DNS hacked ... ? Roberto Jung Drebes
crashing wingates G23
Re: (spoofed) RPC portmapper set/unset Theo de Raadt
Re: your mail Cacaio Torquato
Re: your mail Casper Dik
Re: Xinetd /tmp race? Kevin Vajk
Re: crashing wingates Eric Wanner
Administrivia Aleph One
Vulnerability in Netscape & Microsoft Web browsers Richard Reiner

Sunday, 15 November

Re: Administrivia Chris Tobkin
Re: (spoofed) RPC portmapper set/unset Bill Paul
SerialPOP DoS Philip Stoev
Re: crashing wingates Noam Rathaus
Re: Xinetd /tmp race? (long) Marc Heuse
Re: ISS Security Advisory: Hidden community string in SNMP Raphael Muzzio
Re: ISS Security Advisory: Hidden community string in SNMP sugarat

Monday, 16 November

Re: ISS Security Advisory: Hidden community string in SNMP Matt M. Morris
Security Bulletins Digest (fwd) Piotr Strzy¿ewski
Re: crashing wingates Kotu Srinivasa Reddy
Re: ISS Security Advisory: Hidden community string in SNMP Matt M. Morris
Re: ISS Security Advisory: Hidden community string in SNMP sugarat
nftp vulnerability (fwd) Eric Wanner
KDE 1.0's klock can be used to gain root priveledges HD Moore
Re: open() races in general Glynn Clements
ISSalert: ISS Security Update Aleph One

Tuesday, 17 November

Re: ISS Security Advisory: Hidden community string in SNMP Matt M. Morris
Lynx Artur Grabowski
Re: ISSalert: ISS Security Update topher
Re: KDE 1.0's klock can be used to gain root priveledges Phillip Vandry
NAI-30: Windows NT SNMP Vulnerabilities Security Research Labs
Re: [Linux] klogd 1.3-22 buffer overflow Martin Schulze
Re: [Linux] klogd 1.3-22 buffer overflow Mike
Re: [Linux] klogd 1.3-22 buffer overflow security () PENGUIN NET AU

Wednesday, 18 November

Re: NAI-30: Windows NT SNMP Vulnerabilities David LeBlanc
Update to Microsoft Security Bulletin (MS98-015) Aleph One
Multiple KDE security vulnerabilities (root compromise) David G. Andersen
Sun Security Bulletin #00179 Aleph One
Re: NAI-30: Windows NT SNMP Vulnerabilities Dave G.
Re: NAI-30: Windows NT SNMP Vulnerabilities Friedrichs, Oliver
Re: KDE Screensaver vulnerability Jason Axley
Re: KDE Screensaver vulnerability pedward () WEBCOM COM
KDE Screensaver vulnerability Christian Esken
'sudo' recommendations Brian Martin
Re: KDE Screensaver vulnerability pedward () WEBCOM COM
Re: KDE Screensaver vulnerability Henrik Nordstrom
Re: 'sudo' recommendations Cy Schubert
Re: NAI-30: Windows NT SNMP Vulnerabilities David LeBlanc
Re: Old IRC Client bug Re-Applied Security Admin
Vulnerability in Samba on RedHat, Caldera and PHT TurboLinux Andrew Tridgell
Re: 'sudo' recommendations Alexey Kuzmichev

Thursday, 19 November

Re: Sun Security Bulletin #00179 Jonathan A. Zdziarski
The Son of Cuartango Hole condor () SEKURE ORG
IRIX Vulnerability in ToolTalk RPC Service SGI Security Coordinator
Re: Vulnerability in Netscape & Microsoft Web browsers Paul Shields
RSI.0011.11-09-98.AIX.INFOD RSI Advise
SunOS 4.1.4 Patch #105260-01 L. Granquist
NetBSD Security Advisory 1998-005 matthew green

Friday, 20 November

Re: Vulnerability in Samba on RedHat, Caldera and PHT TurboLinux bobort () ABACUS DORM REED EDU
IRIX chost/gr_osview vulnerabilities Klaus
Re: Old IRC Client bug Re-Applied IRCop
Microsoft Security Bulletin (MS98-017) Aleph One

Saturday, 21 November

Freestats.com CGI vulnerability John Carlton

Monday, 23 November

Netscape Communicator 4.5 can read local files Georgi Guninski
Re: Netscape Communicator 4.5 can read local files GNSS Research Division
Re: Netscape Communicator 4.5 can read local files Bill Lavalette
Re: Netscape Communicator 4.5 can read local files The Spirit of the Black Panther
Re: Netscape Communicator 4.5 can read local files Trev
Vulnerability in IRIX autofsd SGI Security Coordinator

Tuesday, 24 November

Re: Freestats.com CGI vulnerability Aviram Jenik
Re: Freestats.com CGI vulnerability Aviram Jenik
Re: Netscape Communicator 4.5 can read local files Andrew McNaughton
Re: Netscape Communicator 4.5 can read local files Ryan Russell

Wednesday, 25 November

Re: Netscape Communicator 4.5 can read local files kpm
APC PowerNet SNMP Adapter Security Issues - Beta Firmware Paul Mansfield
Re: Netscape Communicator 4.5 can read local files Ben Collins
Re: Netscape Communicator 4.5 can read local files Pavel Kankovsky
Re: Netscape Communicator 4.5 can read local files Terence Christopher Haddock
Re: Netscape Communicator 4.5 can read local files Ben Collins
Re: Netscape Communicator 4.5 can read local files Terence Christopher Haddock
Re: Netscape Communicator 4.5 can read local files Sven Carstens
Re: Netscape Communicator 4.5 can read local files Trev
XFree86 3.3.3 Released Aleph One

Thursday, 26 November

Re: IRIX chost/gr_osview vulnerabilities Knut Hellebø
Re: Netscape Communicator 4.5 can read local files Michael Teichmann
Re: Netscape Communicator 4.5 can read local files Norbert Luckhardt

Friday, 27 November

Re: Netscape Communicator 4.5 can read local files Trev
Java Redirect Bug - Netscpape 4.0[678] and 4.5 Keith Woodard

Saturday, 28 November

ipfwadm has pseudo-DoS ;) Domas Mituzas
Debian: Security flaw in FSP Vanja Hrustic

Sunday, 29 November

RSI.0010a.11-29-98.IRIX.AUTOFSD RSI Advise
Re: Java Redirect Bug - Netscpape 4.0[678] and 4.5 spencer

Monday, 30 November

Debian: Security flaw in FSP David Damerell
Re: Java Redirect Bug - Netscpape 4.0[678] and 4.5 Sander Goudswaard
Re: Netscape Communicator 4.5 can read local files Todd C. Campbell
Re: RedHat 5.2 lrzsz-0.12.14-5 have serious security hole Yuri Kuzmenko
Security bugs in Excite for Web Servers 1.1 Michael Gerdts