Weekly Vulnerabilities Reports > January 28 to February 3, 2002

Overview

15 new vulnerabilities reported during this period, including 2 critical vulnerabilities and 7 high severity vulnerabilities. This weekly summary report vulnerabilities in 16 products from 15 vendors including Mozilla, Redhat, SGI, Linux, and Debian. Vulnerabilities are notably categorized as .

  • 12 reported vulnerabilities are remotely exploitables.
  • 15 reported vulnerabilities are exploitable by an anonymous user.
  • Mozilla has the most reported vulnerabilities, with 5 reported vulnerabilities.
  • Mozilla has the most reported critical vulnerabilities, with 1 reported vulnerabilities.

TOTAL
VULNERABILITIES
CRITICAL RISK
VULNERABILITIES
HIGH RISK
VULNERABILITIES
MEDIUM RISK
VULNERABILITIES
LOW RISK
VULNERABILITIES
REMOTELY
EXPLOITABLE
LOCALLY
EXPLOITABLE
EXPLOIT
AVAILABLE
EXPLOITABLE
ANONYMOUSLY
AFFECTING
WEB APPLICATION

Vulnerability Details

The following table list reported vulnerabilities for the period covered by this report:

Expand/Hide

2 Critical Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2002-01-31 CVE-2002-0007 Mozilla Authentication Bypass vulnerability in BugZilla LDAP

CGI.pl in Bugzilla before 2.14.1, when using LDAP, allows remote attackers to obtain an anonymous bind to the LDAP server via a request that does not include a password, which causes a null password to be sent to the LDAP server.

10.0
2002-01-31 CVE-2002-0005 AOL Remote Buffer Overflow in AOL Instant Messenger

Buffer overflow in AOL Instant Messenger (AIM) 4.7.2480, 4.8.2616, and other versions allows remote attackers to execute arbitrary code via a long argument in a game request (AddGame).

10.0

7 High Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2002-01-31 CVE-2002-0045 Openldap
Redhat
slapd in OpenLDAP 2.0 through 2.0.19 allows local users, and anonymous users before 2.0.8, to conduct a "replace" action on access controls without any values, which causes OpenLDAP to delete non-mandatory attributes that would otherwise be protected by ACLs.
7.5
2002-01-31 CVE-2002-0010 Mozilla Unspecified vulnerability in Mozilla Bugzilla

Bugzilla before 2.14.1 allows remote attackers to inject arbitrary SQL code and create files or gain privileges via (1) the sql parameter in buglist.cgi, (2) invalid field names from the "boolean chart" query in buglist.cgi, (3) the mybugslink parameter in userprefs.cgi, (4) a malformed bug ID in the buglist parameter in long_list.cgi, and (5) the value parameter in editusers.cgi, which allows groupset privileges to be modified by attackers with blessgroupset privileges.

7.5
2002-01-31 CVE-2002-0008 Mozilla Unspecified vulnerability in Mozilla Bugzilla

Bugzilla before 2.14.1 allows remote attackers to (1) spoof a user comment via an HTTP request to process_bug.cgi using the "who" parameter, instead of the Bugzilla_login cookie, or (2) post a bug as another user by modifying the reporter parameter to enter_bug.cgi, which is passed to post_bug.cgi.

7.5
2002-01-31 CVE-2002-0002 Stunnel
Engardelinux
Mandrakesoft
Redhat
Format string vulnerability in stunnel before 3.22 when used in client mode for (1) smtp, (2) pop, or (3) nntp allows remote malicious servers to execute arbitrary code.
7.5
2002-01-30 CVE-2001-1457 Nobreak Technologies Remote Security vulnerability in CrazyWWWBoard

Buffer overflow in CrazyWWWBoard 2000p4 and 2000LEp5 allows remote attackers to execute arbitrary code via a long HTTP_USER_AGENT CGI environment variable.

7.5
2002-01-31 CVE-2002-0043 Todd Miller Unspecified vulnerability in Todd Miller Sudo

sudo 1.6.0 through 1.6.3p7 does not properly clear the environment before calling the mail program, which could allow local users to gain root privileges by modifying environment variables and changing how the mail program is invoked.

7.2
2002-01-31 CVE-2001-0891 SGI
Cray
Format string vulnerability in NQS daemon (nqsdaemon) in NQE 3.3.0.16 for CRAY UNICOS and SGI IRIX allows a local user to gain root privileges by using qsub to submit a batch job whose name contains formatting characters.
7.2

5 Medium Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2002-01-31 CVE-2002-0047 Olaf Titz Unspecified vulnerability in Olaf Titz Cipe

CIPE VPN package before 1.3.0-3 allows remote attackers to cause a denial of service (crash) via a short malformed packet.

5.0
2002-01-31 CVE-2002-0046 Linux Remote Security vulnerability in Linux Kernel 2.6.20.1

Linux kernel, and possibly other operating systems, allows remote attackers to read portions of memory via a series of fragmented ICMP packets that generate an ICMP TTL Exceeded response, which includes portions of the memory in the response packet.

5.0
2002-01-31 CVE-2002-0038 SGI Unspecified vulnerability in SGI Irix

Vulnerability in the cache-limiting function of the unified name service daemon (nsd) in IRIX 6.5.4 through 6.5.11 allows remote attackers to cause a denial of service by forcing the cache to fill the disk.

5.0
2002-01-31 CVE-2002-0011 Mozilla Unspecified vulnerability in Mozilla Bugzilla

Information leak in doeditvotes.cgi in Bugzilla before 2.14.1 may allow remote attackers to more easily conduct attacks on the login.

5.0
2002-01-31 CVE-2002-0009 Mozilla Unspecified vulnerability in Mozilla Bugzilla

show_bug.cgi in Bugzilla before 2.14.1 allows a user with "Bugs Access" privileges to see other products that are not accessible to the user, by submitting a bug and reading the resulting Product pulldown menu.

5.0

1 Low Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2002-01-31 CVE-2002-0044 GNU
Debian
Redhat
GNU Enscript 1.6.1 and earlier allows local users to overwrite arbitrary files of the Enscript user via a symlink attack on temporary files.
3.6