hat software vulnerabilities
vulnerabilities.aspcode.net
Searching hat software vulnerabilities
Denial of service in IP protocol logger (ippl)
protocol
|
service
|
logger
|
Denial
|
Denial of service in IP protocol logger (ippl) on Red Hat and Debian Linux.
Xsession in Red Hat Linux 6.1 and earlier can a
anotherlevel
|
restricted
|
execution
|
accounts
|
Xsession
|
starting
|
earlier
|
bypass
|
allow
|
gnome
|
Linux
|
users
|
local
|
file
|
Hat
|
kdm
|
can
|
Red
|
kde
|
Xsession in Red Hat Linux 6.1 and earlier can allow local users with restricted accounts to bypass execution of the .xsession file by starting kde, gnome or anotherlevel from kdm.
Linuxconf on Red Hat Linux 6.0 and earlier does
PAM-based
|
Linuxconf
|
properly
|
shutdown
|
disable
|
command
|
service
|
earlier
|
denial
|
access
|
local
|
allow
|
cause
|
users
|
could
|
Linux
|
which
|
does
|
Red
|
Hat
|
not
|
Linuxconf on Red Hat Linux 6.0 and earlier does not properly disable PAM-based access to the shutdown command, which could allow local users to cause a denial of service.
dumpreg in Red Hat Linux 5.1 opens /dev/mem wit
/dev/mem
|
service
|
dumpreg
|
access
|
denial
|
allows
|
O_RDWR
|
local
|
users
|
cause
|
opens
|
which
|
Linux
|
Red
|
Hat
|
dumpreg in Red Hat Linux 5.1 opens /dev/mem with O_RDWR access, which allows local users to cause a denial of service (crash) by redirecting fd 1 (stdout) to the kernel.
abuse.console in Red Hat 2.1 uses relative path
abuseconsole
|
pathnames
|
arbitrary
|
commands
|
relative
|
program
|
execute
|
points
|
allows
|
Trojan
|
users
|
horse
|
local
|
undrv
|
which
|
path
|
uses
|
find
|
Red
|
Hat
|
via
|
abuse.console in Red Hat 2.1 uses relative pathnames to find and execute the undrv program, which allows local users to execute arbitrary commands via a path that points to a Trojan horse program.
An installation of Red Hat uses DES password en
installation
|
encryption
|
password
|
uses
|
Red
|
Hat
|
DES
|
An installation of Red Hat uses DES password encryption with crypt() for the initial password, instead of md5.
The Red Hat Linux su program does not log faile
attackers
|
password
|
guessing
|
process
|
guesses
|
conduct
|
program
|
allows
|
before
|
killed
|
failed
|
Linux
|
which
|
local
|
force
|
brute
|
times
|
does
|
log
|
Red
|
not
|
out
|
Hat
|
The Red Hat Linux su program does not log failed password guesses if the su process is killed before it times out, which allows local attackers to conduct brute force password guessing.
Red Hat 6.0 allows local users to gain root acc
password
|
booting
|
hitting
|
access
|
prompt
|
allows
|
single
|
local
|
users
|
user
|
gain
|
root
|
Red
|
Hat
|
Red Hat 6.0 allows local users to gain root access by booting single user and hitting ^C at the password prompt.
The web GUI for the Linux Virtual Server (LVS)
Virtual
|
Server
|
Linux
|
web
|
GUI
|
The web GUI for the Linux Virtual Server (LVS) software in the Red Hat Linux Piranha package has a backdoor password that allows remote attackers to execute arbitrary commands.
ORBit and esound in Red Hat Linux 6.1 do not us
authentication
|
sufficiently
|
numbers
|
allows
|
random
|
esound
|
local
|
users
|
ORBit
|
guess
|
which
|
Linux
|
keys
|
not
|
use
|
Hat
|
Red
|
ORBit and esound in Red Hat Linux 6.1 do not use sufficiently random numbers, which allows local users to guess the authentication keys.
ORBit and gnome-session in Red Hat Linux 6.1 al
gnome-session
|
attackers
|
program
|
remote
|
allows
|
crash
|
ORBit
|
Linux
|
Red
|
Hat
|
ORBit and gnome-session in Red Hat Linux 6.1 allows remote attackers to crash a program.
screen and rxvt in Red Hat Linux 6.0 do not pro
properly
|
devices
|
screen
|
allows
|
which
|
write
|
other
|
local
|
users
|
Linux
|
modes
|
rxvt
|
ttys
|
Red
|
Hat
|
set
|
not
|
tty
|
screen and rxvt in Red Hat Linux 6.0 do not properly set the modes of tty devices, which allows local users to write to other ttys.
Red Hat Linux 6.0 installs the /dev/pts file sy
installs
|
/dev/pts
|
insecure
|
devices
|
system
|
allows
|
local
|
write
|
users
|
other
|
Linux
|
modes
|
which
|
file
|
Red
|
tty
|
Hat
|
Red Hat Linux 6.0 installs the /dev/pts file system with insecure modes, which allows local users to write to other tty devices.
Buffer overflow in xconq and cconq game program
environmental
|
privileges
|
additional
|
programs
|
variable
|
overflow
|
allows
|
Buffer
|
users
|
cconq
|
local
|
Linux
|
xconq
|
long
|
USER
|
gain
|
game
|
Hat
|
Red
|
via
|
Buffer overflow in xconq and cconq game programs on Red Hat Linux allows local users to gain additional privileges via long USER environmental variable.
Buffer overflow in xconq and cconq game program
environmental
|
additional
|
privileges
|
programs
|
overflow
|
variable
|
DISPLAY
|
allows
|
Buffer
|
xconq
|
cconq
|
users
|
Linux
|
local
|
long
|
gain
|
game
|
Hat
|
Red
|
via
|
Buffer overflow in xconq and cconq game programs on Red Hat Linux allows local users to gain additional privileges via long DISPLAY environmental variable.
umb-scheme 3.2-11 for Red Hat Linux is installe
world-writeable
|
umb-scheme
|
installed
|
Linux
|
32-11
|
files
|
Red
|
Hat
|
umb-scheme 3.2-11 for Red Hat Linux is installed with world-writeable files.
DiskCheck script diskcheck.pl in Red Hat Linux
diskcheckpl
|
arbitrary
|
DiskCheck
|
overwrite
|
symlink
|
script
|
create
|
attack
|
allows
|
files
|
Linux
|
local
|
users
|
Red
|
Hat
|
via
|
DiskCheck script diskcheck.pl in Red Hat Linux allows local users to create or overwrite arbitrary files via a symlink attack.
dump in Red Hat Linux 6.2 trusts the pathname s
environmental
|
privileges
|
specified
|
modifying
|
variable
|
pathname
|
program
|
allows
|
trusts
|
obtain
|
Trojan
|
point
|
horse
|
users
|
which
|
Linux
|
local
|
dump
|
root
|
Red
|
RSH
|
Hat
|
dump in Red Hat Linux 6.2 trusts the pathname specified by the RSH environmental variable, which allows local users to obtain root privileges by modifying the RSH variable to point to a Trojan horse program.
restore 0.4b15 and earlier in Red Hat Linux 6.2
environmental
|
privileges
|
modifying
|
specified
|
pathname
|
variable
|
restore
|
earlier
|
program
|
allows
|
obtain
|
trusts
|
Trojan
|
04b15
|
horse
|
point
|
which
|
Linux
|
local
|
users
|
root
|
Hat
|
Red
|
RSH
|
restore 0.4b15 and earlier in Red Hat Linux 6.2 trusts the pathname specified by the RSH environmental variable, which allows local users to obtain root privileges by modifying the RSH variable to point to a Trojan horse program.
rhmask 1.0-9 in Red Hat Linux 7.1 allows local
overwrite
|
arbitrary
|
symlink
|
allows
|
rhmask
|
attack
|
files
|
users
|
Linux
|
local
|
10-9
|
mask
|
file
|
Hat
|
via
|
Red
|
rhmask 1.0-9 in Red Hat Linux 7.1 allows local users to overwrite arbitrary files via a symlink attack on the mask file.
Software vulnerabilities results 1 to 20 of 75
Page:
1
2
3
4
►