1998 年に報告されたセキュリティ勧告

[1998-12-10] sshd
ログ中にバッファオーバフロー
[1998-12-07] fte-console
その root 特権が消されていない
[1998-11-26] fsp
不当なユーザ"ftp"の登録
[1998-11-22] zgv
バッファオーバフロー
[1998-11-18] samba
安全ではないテンポラリファイル
[1998-11-12] junkbuster
バッファオーバーフロー
[1998-09-22] tcsh
buffer overflow with very long paths
[1998-09-09] bash
problem with very long pathnames
[1998-09-05] nslookup and dig
possible buffer overflows in nslookup and dig
[1998-09-04] rpc.mountd
buffer overflow in mountd
[1998-09-01] minicom
buffer overflows in minicom if suid
[1998-08-29] seyon
root compromise
[1998-08-28] sail
/tmp race in sail
[1998-08-28] apache
vulnerable to a denial of service
[1998-08-28] sendsys
remote denial of service if using sendsys report mechanism
[1998-08-28] lprm
buffer overflows allowing local root access
[1998-08-27] eperl
misinterprets ISINDEX queries
[1998-08-27] ncurses
setuid ncurses programs allow opening arbitrary files
[1998-08-27] mutt
malicious mails can execute arbitrary code
[1998-08-27] cfingerd
potentially allows local root exploits
[1998-08-27] faxsurvey
faxsurvey script executes arbitrary commands
[1998-07-08] filerunner
opens files in /tmp in an insecure manner
[1998-06-13] cxhextrix
buffer overflow, giving access to group games
[1998-05-31] mailx
insecurely opens files in /tmp
[1998-05-30] premail
opens files in /tmp insecurely
[1998-05-30] kdebase
buffer overflow in klock, kvt saves config as root
[1998-05-20] samba
buffer overflows
[1998-05-14] gzip
gzexe allows running arbitrary programs
[1998-05-13] shadow su
problem with su
[1998-05-09] procps
file creation and corruption bug in XConsole
[1998-05-08] super
displaying files despite lack of permissions
[1998-05-08] irc
allows remote to send arbitrary characters to local terminal
[1998-04-08] bind
buffer overflow causing potential remote root exploits, denial of service
[1998-03-17] perl
vulnerable to symlink attack
[1998-03-17] netstd
routed permits remote user file overwrite
[1998-03-17] lincity
potential buffer overruns
[1998-03-17] gzip
potential buffer overflow executable
[1998-03-17] gcc
vulnerable to symlink attack
[1998-02-17] textutils
sort and tac vulnerable to symlink attack
[1998-02-11] dwww
Shell meta-characters permitted
[1998-01-12] sudo
sudo allowed users to run any root command
[1998-01-12] smail
UUCP exploit under smail
[1998-01-10] deliver
buffer overflow