Network Security News – Wednesday, November 09, 2005 Events
F-Secure Anti-Virus Internet Gatekeeper/Linux Gateway license_suid.cgi Local Privilege Escalation
F-Secure Anti-Virus Internet Gatekeeper for Linux and F-Secure Anti-Virus Linux Gateway contain a flaw that may allow a malicious local user to elevate privileges to root. The issue is triggered when a user creates a malicious script named license.cgi in the current working directory, and executes the SUID script license_suid.cgi using its full path. The SUID script will execute the malicious script because it looks for it in the working directory. This flaw may lead to a loss of integrity.. Read more at osvdb.org/20547
F-Secure Anti-Virus Internet Gatekeeper/Linux Gateway iptables_suid.cgi Local Privilege Escalation
F-Secure Anti-Virus Internet Gatekeeper for Linux and F-Secure Anti-Virus Linux Gateway contain a flaw that may allow a malicious local user to elevate privileges to root. The issue is triggered when a user creates a malicious script named iptables.cgi in the current working directory, and executes the SUID script iptables_suid.cgi using its full path. The SUID script will execute the malicious script because it looks for it in the working directory. This flaw may lead to a loss of integrity.. Read more at osvdb.org/20548
F-Secure Anti-Virus Internet Gatekeeper/Linux Gateway htpasswd_suid.cgi Local Privilege Escalation
F-Secure Anti-Virus Internet Gatekeeper for Linux and F-Secure Anti-Virus Linux Gateway contain a flaw that may allow a malicious local user to elevate privileges to root. The issue is triggered when a user creates a malicious script named htpasswd.cgi in the current working directory, and executes the SUID script htpasswd_suid.cgi using its full path. The SUID script will execute the malicious script because it looks for it in the working directory. This flaw may lead to a loss of integrity.. Read more at osvdb.org/20545
F-Secure Anti-Virus Internet Gatekeeper/Linux Gateway ifconfig_suid.cgi Local Privilege Escalation
F-Secure Anti-Virus Internet Gatekeeper for Linux and F-Secure Anti-Virus Linux Gateway contain a flaw that may allow a malicious local user to elevate privileges to root. The issue is triggered when a user creates a malicious script named ifconfig.cgi in the current working directory, and executes the SUID script ifconfig_suid.cgi using its full path. The SUID script will execute the malicious script because it looks for it in the working directory. This flaw may lead to a loss of integrity.. Read more at osvdb.org/20513
F-Secure Anti-Virus Internet Gatekeeper/Linux Gateway hostname_suid.cgi Local Privilege Escalation
F-Secure Anti-Virus Internet Gatekeeper for Linux and F-Secure Anti-Virus Linux Gateway contain a flaw that may allow a malicious local user to elevate privileges to root. The issue is triggered when a user creates a malicious script named hostname.cgi in the current working directory, and executes the SUID script hostname_suid.cgi using its full path. The SUID script will execute the malicious script because it looks for it in the working directory. This flaw may lead to a loss of integrity.. Read more at osvdb.org/20541
F-Secure Anti-Virus Internet Gatekeeper/Linux Gateway pattern_autoup_suid.cgi Local Privilege Escalation
F-Secure Anti-Virus Internet Gatekeeper for Linux and F-Secure Anti-Virus Linux Gateway contain a flaw that may allow a malicious local user to elevate privileges to root. The issue is triggered when a user creates a malicious script named pattern_autoup.cgi in the current working directory, and executes the SUID script pattern_autoup_suid.cgi using its full path. The SUID script will execute the malicious script because it looks for it in the working directory. This flaw may lead to a loss of integrity.. Read more at osvdb.org/20550
F-Secure Anti-Virus Internet Gatekeeper/Linux Gateway pattern_up_suid.cgi Local Privilege Escalation
F-Secure Anti-Virus Internet Gatekeeper for Linux and F-Secure Anti-Virus Linux Gateway contain a flaw that may allow a malicious local user to elevate privileges to root. The issue is triggered when a user creates a malicious script named pattern_up.cgi in the current working directory, and executes the SUID script pattern_up_suid.cgi using its full path. The SUID script will execute the malicious script because it looks for it in the working directory. This flaw may lead to a loss of integrity.. Read more at osvdb.org/20546
F-Secure Anti-Virus Internet Gatekeeper/Linux Gateway proxy_suid.cgi Local Privilege Escalation
F-Secure Anti-Virus Internet Gatekeeper for Linux and F-Secure Anti-Virus Linux Gateway contain a flaw that may allow a malicious local user to elevate privileges to root. The issue is triggered when a user creates a malicious script named proxy.cgi in the current working directory, and executes the SUID script proxy_suid.cgi using its full path. The SUID script will execute the malicious script because it looks for it in the working directory. This flaw may lead to a loss of integrity.. Read more at osvdb.org/20538
F-Secure Anti-Virus Internet Gatekeeper/Linux Gateway spam_list_suid.cgi Local Privilege Escalation
F-Secure Anti-Virus Internet Gatekeeper for Linux and F-Secure Anti-Virus Linux Gateway contain a flaw that may allow a malicious local user to elevate privileges to root. The issue is triggered when a user creates a malicious script named spam_list.cgi in the current working directory, and executes the SUID script spam_list_suid.cgi using its full path. The SUID script will execute the malicious script because it looks for it in the working directory. This flaw may lead to a loss of integrity.. Read more at osvdb.org/20551
F-Secure Anti-Virus Internet Gatekeeper/Linux Gateway version_suid.cgi Local Privilege Escalation
F-Secure Anti-Virus Internet Gatekeeper for Linux and F-Secure Anti-Virus Linux Gateway contain a flaw that may allow a malicious local user to elevate privileges to root. The issue is triggered when a user creates a malicious script named version.cgi in the current working directory, and executes the SUID script version_suid.cgi using its full path. The SUID script will execute the malicious script because it looks for it in the working directory. This flaw may lead to a loss of integrity.. Read more at osvdb.org/20540
Vuln: Clam Anti-Virus ClamAV TNEF File Handling Denial Of Service Vulnerability
Clam Anti-Virus ClamAV TNEF File Handling Denial Of Service Vulnerability. Read more at securityfocus.com/bid/15316
Vuln: Clam Anti-Virus ClamAV CAB File Handling Denial Of Service Vulnerability
Clam Anti-Virus ClamAV CAB File Handling Denial Of Service Vulnerability. Read more at securityfocus.com/bid/15317
Vuln: Clam Anti-Virus ClamAV FSG File Handling Buffer Overflow Vulnerability
Clam Anti-Virus ClamAV FSG File Handling Buffer Overflow Vulnerability. Read more at securityfocus.com/bid/15318
Vuln: Clam Anti-Virus ClamAV OLE2 File Handling Denial Of Service Vulnerability
Clam Anti-Virus ClamAV OLE2 File Handling Denial Of Service Vulnerability. Read more at securityfocus.com/bid/15101
Re: Hidden accounts on sony vaio laptops
Re: Hidden accounts on sony vaio laptops. Read more at securityfocus.com/archive/1/416053
Oracle DBMS_ASSERT and the October 2005 CPU
Oracle DBMS_ASSERT and the October 2005 CPU. Read more at securityfocus.com/archive/1/416046
Oracle October 2005 CPU Problems
Oracle October 2005 CPU Problems. Read more at securityfocus.com/archive/1/416045
Call For Papers
Call For Papers. Read more at securityfocus.com/archive/1/416050
Leave a Reply