Bugtraq: by author

231 messages starting Mar 11 98 and ending Mar 07 98
Date index | Thread index | Author index


Alan Cox

Re: the purpose of dynamic memory allocation Alan Cox (Mar 11)

Aleph One

WinNT Widespread Teardrop Exploit Aleph One (Mar 03)
FreeBSD Security Advisory: FreeBSD-SA-98:01.land Aleph One (Mar 12)
Sun Security Bulletin #00165 Aleph One (Mar 11)
FreeBSD Security Advisory: FreeBSD-SA-98:02.mmap Aleph One (Mar 12)
NTFS Alternate Data Streams Aleph One (Mar 20)
HPSBUX9803-077 Security Vulnerability with inetd on HP-UX Aleph One (Mar 30)
Solaris printd security vulnerability Aleph One (Mar 11)
Update on wide-spread NewTear Denial of Service attacks Aleph One (Mar 04)
Re: strcpy versus strncpy Aleph One (Mar 04)
Protocol Aleph One (Mar 24)
Re: IE 4 Bug (Crash with frames) Aleph One (Mar 20)
Re: strcpy versus strncpy Aleph One (Mar 02)
IE 4.01 bugs in Win95 & WinNT. (long) Aleph One (Mar 16)
MDaemon SMTP Server Buffer Overflow's Aleph One (Mar 10)
Administrivia Aleph One (Mar 10)
Re: strcpy versus strncpy Aleph One (Mar 04)
Re: MySQL Security Aleph One (Mar 29)
Re: WinSock 2.2. Woes Aleph One (Mar 17)
Ascend Kill II - C version Aleph One (Mar 16)
Rhino9: WinGate Vulnerability Aleph One (Mar 29)
NTCrash2 Aleph One (Mar 25)
Re: strcpy versus strncpy Aleph One (Mar 04)
Re: strcpy versus strncpy Aleph One (Mar 04)
RAS 'save password' problems... Aleph One (Mar 20)

Alexandre Stervinou

Bash: Security problem during compilation time. Alexandre Stervinou (Mar 16)

Alvaro Martinez Echevarria

DoS (and possibly more) on MDaemon for NT/95 Alvaro Martinez Echevarria (Mar 10)

Andreas Jaeger

Re: Linux libc5 'bug' in mkstemp(). Andreas Jaeger (Mar 10)

Andy Church

Re: strcpy versus strncpy Andy Church (Mar 02)

Ari Heitner

Re: x11amp playlist bug Ari Heitner (Feb 28)

Avi Rubin

List of college and graduate courses in crypto and security Avi Rubin (Mar 05)
Updated list of crypto and security courses Avi Rubin (Mar 09)

Ben Laurie

Re: mysql: MySQL Security Ben Laurie (Mar 31)
Re: apache+ssl 1.13 symlink problem Ben Laurie (Mar 24)
Re: strcpy versus strncpy Ben Laurie (Mar 03)

Bill Becker

Re: BSD/OS 3.0 config_anonftp script Bill Becker (Mar 18)

bjorn smedman

buffer overflow with a twist bjorn smedman (Mar 24)

Bob Tracy - TDS

Re: LinCity Buffer Overflow Bob Tracy - TDS (Mar 16)

Bryan Andregg

Re: overwrite any file with updatedb Bryan Andregg (Mar 02)

bst () INAME COM

Re: Lincity Buffer Overflow bst () INAME COM (Mar 17)
Re: /tmp event logger bst () INAME COM (Mar 16)

Cain

overwrite any file with updatedb Cain (Mar 01)
updatedb stuff Cain (Mar 02)

Casper Dik

Re: Linux libc5 'bug' in mkstemp(). Casper Dik (Mar 10)

Catalin Mitrofan

a better exploit for the old mh ... Catalin Mitrofan (Mar 23)
An exploit for linux mh ver 6.8.4-5 ( update ) ... Catalin Mitrofan (Mar 21)

Chip Salzenberg

Re: Perl bugs (was Re: another /tmp race: `perl -e') Chip Salzenberg (Mar 08)

Chris L. Mason

Re: strcpy versus strncpy Chris L. Mason (Mar 03)
Re: strcpy versus strncpy Chris L. Mason (Mar 03)

Christian Holmqvist

Re: MSIE buffer overrun Christian Holmqvist (Mar 20)

Christopher R. Hertel

Re: WinSock 2.2. Woes Christopher R. Hertel (Mar 20)

Cyril Jaouich

Re: SNI-26: Ascend Router Security Issues Cyril Jaouich (Mar 17)

Dan

More browser bugs. Dan (Mar 26)

Daniel Reed

Re: strcpy versus strncpy Daniel Reed (Mar 02)
Re: Another day, another race - lynx 2.7.1 Daniel Reed (Mar 17)

Darren J Moffat - Sun UK - Consultant Engineer

Re: wtmpx utility for solaris Darren J Moffat - Sun UK - Consultant Engineer (Mar 31)

Dave G.

Re: overwrite any file with updatedb Dave G. (Mar 02)

David LeBlanc

Re: RAS 'save password' problems... David LeBlanc (Mar 22)
Re: the purpose of dynamic memory allocation David LeBlanc (Mar 10)

Dax Kelson

Sumbit Internet Account v1.1 Dax Kelson (Mar 25)

Dean Gaudet

Re: strcpy versus strncpy Dean Gaudet (Mar 02)

Dennis Taylor

Re: another /tmp race: `perl -e' opens temp file not safely Dennis Taylor (Mar 07)

der Mouse

Re: strcpy versus strncpy der Mouse (Mar 04)
Re: strcpy versus strncpy der Mouse (Mar 05)

Development Team

Problems with MDaemon 2.7.1 Development Team (Mar 12)

D. J. Bernstein

the purpose of dynamic memory allocation D. J. Bernstein (Mar 04)

dorqus

Followup: Plaintext passwords in Chase Online Banking dorqus (Mar 21)

dorqus maximus

Plaintext passwords in Chase Online Banking dorqus maximus (Mar 07)
Re: Plaintext passwords in Chase Online Banking dorqus maximus (Mar 08)

Dr. BSD

Re: Another day, another race - lynx 2.7.1 Dr. BSD (Mar 17)

Edwin Li-Kai Liu

Re: strcpy versus strncpy Edwin Li-Kai Liu (Mar 03)

Eivind Eklund

Re: strcpy versus strncpy Eivind Eklund (Mar 03)

Erik Troan

Re: An exploit for linux mh ver 6.8.4-5 ( update ) ... Erik Troan (Mar 21)
SECURITY: new svgalib and kbd now available Erik Troan (Mar 25)
Re: *sigh* another RH5 /tmp problem Erik Troan (Mar 10)

Fiji

Re: Clipboard insecurity Fiji (Mar 30)

g3nR8 f00b4r

BackWeb Server v.3 (Eval) g3nR8 f00b4r (Mar 10)

gareth greenaway

Possible Bug in CDE on HP-UX gareth greenaway (Mar 09)

Georgi Guninski

MSIE buffer overrun Georgi Guninski (Mar 20)

Greg Alexander

Linux libc5 'bug' in mkstemp(). Greg Alexander (Mar 09)

Henri Karrenbeld

Re: Winsock 2.0 DoS Henri Karrenbeld (Mar 12)

Henrik Nordstrom

Re: Simple way to bypass squid ACLs Henrik Nordstrom (Mar 03)

HKirk

Hole. HKirk (Mar 28)

J.A. Gutierrez

IRIX performer_tools bug J.A. Gutierrez (Mar 16)

Jeff Johnson

x11amp bug Jeff Johnson (Mar 01)

Jeff Murphy

Re: overwrite any file with updatedb Jeff Murphy (Mar 02)

Jeffrey Hutzelman

Re: the purpose of dynamic memory allocation Jeffrey Hutzelman (Mar 10)

Jeremy Brinkley

Re: Possible Bug in CDE on HP-UX Jeremy Brinkley (Mar 10)

jericho () DIMENSIONAL COM

InfoSecurity News jericho () DIMENSIONAL COM (Mar 13)

Jim Credland

Clipboard insecurity Jim Credland (Mar 30)

joey.wheel

Chase Bank joey.wheel (Mar 13)

Joe Zbiciak

Re: strcpy versus strncpy Joe Zbiciak (Mar 02)

John Goerzen

Re: LinCity Buffer Overflow John Goerzen (Mar 17)

John Robinson

Winsock 2.0 DoS John Robinson (Mar 12)
Winsock 2.0 DoS John Robinson (Mar 11)

Jon

SLMail 2.6 DoS - Imail also Jon (Mar 11)

Julie Haugh

Re: (forw) Re: bug in su (Slackware 3.4) Julie Haugh (Mar 23)

Karl G - NOC Admin

Majordomo /tmp exploit Karl G - NOC Admin (Mar 26)

Karl Koscher

AOL Instant Messenger Bug... AGAIN! Karl Koscher (Mar 20)

Kill9

/tmp system shortcomings Kill9 (Mar 08)

KiloByte

Modified floppies can crash Linux KiloByte (Mar 23)

Kit Knox

Ascend Kill II - perl version Kit Knox (Mar 17)
Ascend Kill II - Fix Now Available Kit Knox (Mar 19)

Kragen

Re: overwrite any file with updatedb Kragen (Mar 02)
Re: overwrite any file with updatedb Kragen (Mar 02)
Re: strcpy versus strncpy Kragen (Mar 03)

Kusche, Klaus

MS Word connected to DB/2: Cleartext host uid & pwd in document! Kusche, Klaus (Mar 18)

Lewis Eatherton

Re: Eudora Pro 4.0 attachment/long filename problem Lewis Eatherton (Mar 30)

Lloyd Vancil

Re: IE 4 Bug (Crash with frames) Lloyd Vancil (Mar 19)

Lumpy Lynx

Re: Very, very ugly remote lynx 2.7.1 hole Lumpy Lynx (Mar 17)

Lynn Kyle

MS Personal Web Server Lynn Kyle (Mar 22)

Magosanyi Arpad

Lotus Notes security hole Magosanyi Arpad (Mar 20)

Marc Slemko

New FrontPage98 Server Extensions Release (fwd) Marc Slemko (Mar 20)

Mark A. Spencer

/tmp issue with savetextmode Mark A. Spencer (Mar 23)
*sigh* another RH5 /tmp problem Mark A. Spencer (Mar 09)

Mark Schaefer

Ascend Filter Setup Mark Schaefer (Mar 16)

Mark Symons

Re: SLMail 2.6 DoS - Imail also Mark Symons (Mar 17)

Mark Walker

Re: strcpy versus strncpy Mark Walker (Mar 03)

Mark Whitis

Re: strcpy versus strncpy Mark Whitis (Mar 04)

martin Dolphin

Re: RAS 'save password' problems... martin Dolphin (Mar 23)
Re: RAS 'save password' problems... martin Dolphin (Mar 22)

Martin Schulze

Re: bug in su (Slackware 3.4) Martin Schulze (Mar 22)
Re: bug in su (Slackware 3.4) Martin Schulze (Mar 22)

Matt Drown

Re: More browser bugs. Matt Drown (Mar 27)

Matt Nichols

Re: Possible Bug in CDE on HP-UX Matt Nichols (Mar 10)

matt sawkill

Re: MSIE buffer overrun matt sawkill (Mar 20)

Michael Ballbach

updatedb: sort patch Michael Ballbach (Mar 02)

Michael Widenius

mysql: MySQL Security Michael Widenius (Mar 29)
FW: mysql: Trivial mSQL/MySQL DoS method? (fwd) Michael Widenius (Mar 26)
Re: mysql: MySQL Security Michael Widenius (Mar 31)

Michael Young - 716-475-6031

Re: WinNT Widespread Teardrop Exploit Michael Young - 716-475-6031 (Mar 04)

Michal Zalewski

Another day, another race - lynx 2.7.1 Michal Zalewski (Mar 17)
Very, very ugly remote lynx 2.7.1 hole Michal Zalewski (Mar 17)
ncftp 2.4.3 overflow / su killing Michal Zalewski (Mar 24)
Midnight Commander /tmp race Michal Zalewski (Mar 15)
/tmp event logger Michal Zalewski (Mar 14)
ncftp 2.4.2 MkDirs bug Michal Zalewski (Mar 19)
Vunerable shell scripts Michal Zalewski (Mar 14)

Mikael Brandstrom

Re: wtmpx utility for solaris Mikael Brandstrom (Mar 31)

Mike Gleason

Re: apache+ssl 1.13 symlink problem; NcFTP 2.4.2+ Mike Gleason (Mar 24)
Clarification Mike Gleason (Mar 24)

Mike Zimmerman

WinGate Intermediary Fix/Update Mike Zimmerman (Mar 26)
Eudora Pro/IE bugs Mike Zimmerman (Mar 30)

Miquel van Smoorenburg

Re: An exploit for linux mh ver 6.8.4-5 ( update ) ... Miquel van Smoorenburg (Mar 21)
Re: An exploit for linux mh ver 6.8.4-5 ( update ) ... Miquel van Smoorenburg (Mar 23)

Morten Welinder

strcpy versus strncpy Morten Welinder (Mar 02)

Niall Smart

Vulnerabilites in some versions of info2www CGI Niall Smart (Mar 03)

Nick Maclaren

Re: strcpy versus strncpy Nick Maclaren (Mar 05)
Re: strcpy versus strncpy Nick Maclaren (Mar 03)

Nigel Reed

Re: Trivial mSQL/MySQL DoS method? Nigel Reed (Mar 26)

Noam Ben-Yochanan

Re: RAS 'save password' problems... Noam Ben-Yochanan (Mar 22)

Ondrej Suchy

apache+ssl 1.13 symlink problem Ondrej Suchy (Mar 24)

Paul McNabb

Re: strcpy versus strncpy Paul McNabb (Mar 05)

Pavel Kankovsky

Re: Midnight Commander /tmp race Pavel Kankovsky (Mar 18)
Re: Midnight Commander /tmp race Pavel Kankovsky (Mar 17)

Pavel Machek

Way to stop /tmp races Pavel Machek (Mar 21)

pedward () WEBCOM COM

Re: strcpy versus strncpy pedward () WEBCOM COM (Mar 03)

Peter van Dijk

/tmp race in Linux kernel source! Peter van Dijk (Mar 15)
bug in su (Slackware 3.4) Peter van Dijk (Mar 15)
easy DoS in most RPC apps Peter van Dijk (Mar 28)
Re: Security problem in Slackware. Peter van Dijk (Mar 13)

Phillip Pudney

Re: ConferenceRoom Exploit [tRa BuG LaBz0rz] Phillip Pudney (Mar 30)

Ralph LoBianco

Re: WinSock 2.2. Woes Ralph LoBianco (Mar 18)

Rick Branson

ConferenceRoom Exploit [tRa BuG LaBz0rz] Rick Branson (Mar 29)

Rommetveit Per Stuve

Re: IE 4 Bug (Crash with frames) Rommetveit Per Stuve (Mar 19)

root

Re: x11amp playlist bug root (Mar 02)
Re: x11amp bug root (Mar 01)

Rop Gonggrijp

Netscape passes mailbox path and message ID as refferer Rop Gonggrijp (Mar 28)

Rubens Kuhl Jr.

Re: MS Personal Web Server Rubens Kuhl Jr. (Mar 22)

Russ

Re: WinSock 2.2. Woes Russ (Mar 18)
Re: MSIE buffer overrun Russ (Mar 20)
Re: Update on wide-spread NewTear Denial of Service attacks Russ (Mar 04)
Win95 Winsock 2.0 DoS Russ (Mar 13)
Re: WinNT Widespread Teardrop Exploit Russ (Mar 04)
Re: More broadcast fun Russ (Mar 17)
Re: Update on wide-spread NewTear Denial of Service attacks Russ (Mar 04)

Ryan

wtmpx utility for solaris Ryan (Mar 30)

Sandu Mihai

MySQL Security Sandu Mihai (Mar 29)

Secure Networks Inc.

SNI-26: Ascend Router Security Issues Secure Networks Inc. (Mar 16)

Seth McGann

Re: WinSock 2.2. Woes Seth McGann (Mar 18)

SGI Security Coordinator

pset Buffer Overrun Vulnerability SGI Security Coordinator (Mar 26)
IMAP/POP Vulnerability SGI Security Coordinator (Mar 25)
Netscape Navigator Security Vulnerabilities SGI Security Coordinator (Mar 26)
SGI Security Advisory 19980301-01-PX - startmidi/stopmidi, SGI Security Coordinator (Mar 12)

sinster () DARKWATER COM

Re: the purpose of dynamic memory allocation sinster () DARKWATER COM (Mar 05)
Re: strcpy versus strncpy sinster () DARKWATER COM (Mar 02)

Solar Designer

edquota(8) feature Solar Designer (Mar 21)

stanislav shalunov

Re: another /tmp race: `perl -e' opens temp file not safely stanislav shalunov (Mar 08)
Re: another /tmp race: `perl -e' opens temp file not safely stanislav shalunov (Mar 08)
Re: another /tmp race: `perl -e' opens temp file not safely stanislav shalunov (Mar 07)
another /tmp race: `perl -e' opens temp file not safely stanislav shalunov (Mar 07)

Steve Bellovin

Re: strcpy versus strncpy Steve Bellovin (Mar 05)

Steven

SLMail 2.6 DoS Steven (Mar 11)

Steven Goldberg - SE - Seattle WA

Re: /usr/dt/bin/dtappgather exploit Steven Goldberg - SE - Seattle WA (Mar 19)

Steven Pritchard

Re: Majordomo /tmp exploit Steven Pritchard (Mar 26)

stevep () ee pdx edu

Re: Winsock 2.0 DoS stevep () ee pdx edu (Mar 12)

Stunt Pope

Trivial mSQL/MySQL DoS method? Stunt Pope (Mar 26)

Suman_Saraf

Security problem in Slackware. Suman_Saraf (Mar 11)

System Administrator

Re: IE 4 Bug (Crash with frames) System Administrator (Mar 19)

T. Freak

LinCity Buffer Overflow T. Freak (Mar 16)
More broadcast fun T. Freak (Mar 14)

Theo de Raadt

Re: another /tmp race: `perl -e' opens temp file not safely Theo de Raadt (Mar 08)
Re: /tmp event logger Theo de Raadt (Mar 15)
Re: another /tmp race: `perl -e' opens temp file not safely Theo de Raadt (Mar 08)
New OpenBSD security web page Theo de Raadt (Mar 06)
Re: another /tmp race: `perl -e' opens temp file not safely Theo de Raadt (Mar 07)
Re: another /tmp race: `perl -e' opens temp file not safely Theo de Raadt (Mar 07)
Re: Another day, another race - lynx 2.7.1 Theo de Raadt (Mar 17)

Theo Van Dinter

Re: ncftp 2.4.2 MkDirs bug Theo Van Dinter (Mar 20)

Thomas H. Ptacek

SNI-27: Vulnerabilities in Sun NIS+ Thomas H. Ptacek (Mar 23)

Thomas Michaux

Ascend Kill Thomas Michaux (Mar 20)

Thomas Roessler

Re: Another day, another race - lynx 2.7.1 Thomas Roessler (Mar 17)

Thomas Sailer

Re: x11amp playlist bug Thomas Sailer (Mar 05)

Thomas Weidauer

IE 4 Bug (Crash with frames) Thomas Weidauer (Mar 18)

Tim Moore

Re: WinSock 2.2. Woes Tim Moore (Mar 18)

Tim Newsham

Re: Update on wide-spread NewTear Denial of Service attacks Tim Newsham (Mar 04)
Re: Update on wide-spread NewTear Denial of Service attacks Tim Newsham (Mar 04)
Re: x11amp playlist bug Tim Newsham (Mar 03)

Tony Hagale

Fwd: Sun Security Bulletin #00166 Tony Hagale (Mar 11)

tqbf () secnet com

Re: the purpose of dynamic memory allocation tqbf () secnet com (Mar 06)

trey

BSD/OS 3.0 config_anonftp script trey (Mar 16)

Vadim Kolontsov

Internet Mail bug Vadim Kolontsov (Mar 30)

Velocet

more testing of Winsock 2.0 DoS Velocet (Mar 12)

Victor Lavrenko

Re: strcpy versus strncpy Victor Lavrenko (Mar 03)

whiz

Eudora Pro 4.0 attachment/long filename problem whiz (Mar 29)
Re: IE 4 Bug (Crash with frames), Variation whiz (Mar 28)

Wietse Venema

dynamic memory allocation considered beneficial Wietse Venema (Mar 05)
Re: strcpy versus strncpy Wietse Venema (Mar 03)

willy () SNOWYOWL CSU AC RU

Re: Midnight Commander /tmp race willy () SNOWYOWL CSU AC RU (Mar 17)

Willy TARREAU

Universal Wrapper Willy TARREAU (Mar 03)

X

r00t Advisory [ LitterMaid Race Condition ] X (Mar 07)