CERT/CC Vulnerability Note 2002/08/27 追加 VU#746251 Novell Netware RCONAG6 fails to validate user password when "Secure IP" is used to establish connection http://www.kb.cert.org/vuls/id/746251
DNS resolve は細工された DNS メッセージを適切なチェックをしていないことが原因で、バッファオーバーフローの問題が存在します。攻撃者にのこセキュリティホールを利用された場合、リモートから任意のコードを実行される可能性があります。
□ 関連情報:
CERT/CC Vulnerability Note 2002/08/27 更新 VU#542971 Multiple vendors' Domain Name System (DNS) stub resolvers vulnerable to buffer overflow via network name and address lookups http://www.kb.cert.org/vuls/id/542971
CERT/CC Vulnerability Note 2002/08/28 更新 VU#803539 Multiple vendors' Domain Name System (DNS) stub resolvers vulnerable to buffer overflow http://www.kb.cert.org/vuls/id/803539
CERT Microsoft Windows SQL Server allows arbitrary queries to be executed via "xp_printstatements" extended procedure http://www.kb.cert.org/vuls/id/939675
CERT Microsoft Windows SQL Server allows arbitrary queries to be executed via "xp_execresultset" extended procedure http://www.kb.cert.org/vuls/id/399531
CERT/CC Vulnerability Note 2002/08/20 追加 VU#399531 Microsoft Windows SQL Server allows arbitrary queries to be executed via "xp_execresultset" extended procedure http://www.kb.cert.org/vuls/id/399531
CERT Vulnerability Note VU#250635 Microsoft Windows Server Message Block (SMB) fails to properly handle SMB_COM_TRANSACTION packets requesting NetServerEnum2 transaction http://www.kb.cert.org/vuls/id/250635
CERT Vulnerability Note VU#342243 Microsoft Windows Server Message Block (SMB) fails to properly handle SMB_COM_TRANSACTION packets requesting NetShareEnum transaction http://www.kb.cert.org/vuls/id/342243
CERT/CC Vulnerability Note VU#311619 Microsoft Windows Server Message Block (SMB) fails to properly handle SMB_COM_TRANSACTION packets requesting NetServerEnum3 transaction http://www.kb.cert.org/vuls/id/311619
CERT/CC Vulnerability Note VU#250635 Microsoft Windows Server Message Block (SMB) fails to properly handle SMB_COM_TRANSACTION packets requesting NetServerEnum2 transaction http://www.kb.cert.org/vuls/id/250635
CERT/CC Vulnerability Note 2002/08/27 追加 VU#342243 Microsoft Windows Server Message Block (SMB) fails to properly handle SMB_COM_TRANSACTION packets requesting NetShareEnum transaction http://www.kb.cert.org/vuls/id/342243
CERT 2002/08/28 追加 Microsoft Windows Terminal Services Advanced Client (TSAC) contains buffer overflow in process that handles input parameters http://www.kb.cert.org/vuls/id/276321
ISS X-Force Database Results 2002/08/29 追加 ie-local-resource-xss (9938) Microsoft Internet Explorer "Local HTML Resource" cross-site scripting variant http://www.iss.net/security_center/static/9938.php
CERT 2002/07/18 追加 Certain MIME types can cause Internet Explorer to execute arbitrary code when rendering HTML http://www.kb.cert.org/vuls/id/980499
CERT 2002/08/27 追加 Microsoft Internet Explorer may handle certain web pages in an incorrect, less restrictive security zone (MS02-023) http://www.kb.cert.org/vuls/id/242891
ISS X-Force Database Results 2002/08/29 追加 ie-local-resource-xss (9938) Microsoft Internet Explorer "Local HTML Resource" cross-site scripting variant http://www.iss.net/security_center/static/9938.php
CERT 2002/08/27 追加 Microsoft Office Web Components allows reading of local files via "LoadText" method by using URL redirection http://www.kb.cert.org/vuls/id/355707