(
日期:][
下一个日期][
线程:][
线程下][
日期索引][
线程索引]
[VOTEPRI] 6 4/11/2000高优先级的候选人
我定义了一个新的VOTEPRI标记定期“高优先级”投票列表。以下6个候选人上周的优先列表的其余部分(感谢克雷格Ozancin敲其他13个,临时决定。)这些候选人都承认由软件供应商。他们只需要一个接受投票。如果你有机会在这些投票,请把你的票给我。谢谢,-史蒂夫= = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = =候选人:可以发表- 2000 - 0050:最终决定:阶段性裁决:修改:建议:20000125分配:20000122类别:科幻参考:报价:915参考:网址:http://www.securityfocus.com/vdb/bottom.html?vid=915参考:阿莱尔:ASB00-01参考:网址:http://www.allaire.com/handlers/index.cfm?ID=13976&Method=Full阿莱尔光谱网络桌面允许经过身份验证的用户访问其他网络桌面部分通过指定明确的url。推断行动:- 2000 - 0050 MOREVOTES-1(1接受,1 ack, 0评论)目前投票:弗伦奇等待修改(1)(1)Ozancin评论:弗雷希> XF: allaire-webtop-access = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = =候选人:可以发表- 2000 - 0051:最终决定:阶段性裁决:修改:建议:20000125分配:20000122类别:科幻参考:报价:916参考:网址:http://www.securityfocus.com/vdb/bottom.html?vid=916参考:阿莱尔:ASB00-02参考:网址:http://www.allaire.com/handlers/index.cfm?ID=13977&Method=Full阿莱尔谱配置向导允许远程攻击者造成拒绝服务通过不断重新提交数据集合索引通过一个URL。推断行动:- 2000 - 0051 MOREVOTES-1(1接受,1 ack, 0评论)目前投票:弗伦奇等待修改(1)(1)Ozancin评论:弗雷希> XF: allaire-spectra-config-dos = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = =候选人:可以发表- 2000 - 0070:最终决定:阶段性裁决:修改:20000204 - 01提议:20000125分配:20000122类别:科幻参考:BINDVIEW: 20000113当地促销漏洞在Windows NT 4参考:网址:http://www.bindview.com/security/advisory/adv_NtImpersonate.html参考:女士:ms00 - 003参考:网址:http://www.microsoft.com/technet/security/bulletin/ms00 - 003. - asp参考:MSKB: Q247869参考:XF: nt-spoofed-lpc-port参考:网址:http://xforce.iss.net/search.php3?type=2&pattern=nt-spoofed-lpc-portNtImpersonateClientOfPort本地过程调用Windows NT 4.0允许本地用户获得特权,又名“欺骗LPC的端口的请求。”Modifications: ADDREF XF:nt-spoofed-lpc-port INFERRED ACTION: CAN-2000-0070 MOREVOTES-1 (1 accept, 3 ack, 0 review) Current Votes: MODIFY(1) Frech NOOP(1) Ozancin Comments: Frech> ADDREF XF:nt-spoofed-lpc-port ================================= Candidate: CAN-2000-0112 Published: Final-Decision: Interim-Decision: Modified: Proposed: 20000208 Assigned: 20000208 Category: CF Reference: BUGTRAQ:20000202 vulnerability in Linux Debian default boot configuration Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=94973075614088&w=2参考网址:http://marc.theaimsgroup.com/?l=bugtraq&m=94952030018431&w=2参考:报价:960参考:网址:http://www.securityfocus.com/vdb/bottom.html?vid=960默认安装Debian Linux使用一个不安全的主引导记录(MBR),允许本地用户从软盘启动期间安装。推断行动:- 2000 - 0112 MOREVOTES-1(1接受,1 ack, 0评论)目前投票:接受(1)科尔等待(2)墙,Ozancin = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = =候选人:可以发表- 2000 - 0165:最终决定:阶段性裁决:修改:建议:20000223分配:20000223类别:科幻参考:BUGTRAQ: 20000210 Re:应用程序代理?参考:FREEBSD: FreeBSD-SA-00:04参考:网址:http://www.securityfocus.com/templates/archive.pike?list=1&date=2000 - 02 - 15 - &msg=pine.bsf.4.21.0002192249290.10784 - 100000 @freefall.freebsd.org参考网址:http://www.securityfocus.com/templates/archive.pike?list=1&date=2000 - 02 - 8 &msg=pine.bsf.4.10.10002100058420.43483 - 100000 @hydrant.intranova.net代表应用程序代理有几个缓冲区溢出,允许远程攻击者执行命令。推断行动:- 2000 - 0165 MOREVOTES-1(1接受,1 ack, 0评论)目前投票:接受(1)科尔等待(3)墙,勒布朗,Ozancin = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = =候选人:可以发表- 2000 - 0173:最终决定:阶段性裁决:修改:建议:20000322分配:20000322类别:科幻参考:上海合作组织:某人- 00.08参考:网址:ftp://ftp.sco.com/sse/security_bulletins/sb - 00.08 a在上海合作组织UnixWare 7.1鳗鱼系统的脆弱性。x允许远程攻击者造成拒绝服务。推断行动:- 2000 - 0173 MOREVOTES-1(1接受,1 ack, 0评论)目前投票:接受布莱克(1)无操作(4)墙,勒布朗,Ozancin,科尔