Security Hole In Shareplex

2001-03-30 Thread Dixie Flatline
Please forward this to the list. Security Hole in Shareplex 2.x -- Summary --- Shareplex (Quest Software's product for Oracle database replication) contains a security hole which can allow local users to read any

HP-UX 11 elm -s possible local egid mail compromise

2001-03-08 Thread Flatline
- Introduction: HP-UX 11.00 ships with a vulnerable version of the elm MUA, it contains a buffer overflow vulnerability in the -s (subject) argument. I found that version 2.5.0 had the bug fixed so I looked for older versions to check and it seems that the most recent version to contain this

Security Hole in Microfocus Cobol

2001-02-12 Thread Dixie Flatline
Summary --- If the AppTrack feature is enabled, the default install of MicroFocus Cobol 4.1 (Merant's commercial suite of cobol utilities) contains a security hole which can lead to root compromise. Specifics - In the default install, /var/mfaslmf is installed mode 777, and