SuSE: 1999: Security Advisory For Pbpg Critical Access Risk
The /usr/bin/pg and /usr/bin/pb tools can be used to read any file on the system.
Find the information you need for your favorite open source distribution .
The /usr/bin/pg and /usr/bin/pb tools can be used to read any file on the system.
The /usr/bin/sccw tool can be used to read any file on the system.
The mars_nwe tools are vulnerable to several buffer overflows.
Several buffer overflows have been found in proftpd which have been verified to be exploitable from an remote attacker. The fixing and finding of new holes is going on for over 2 weeks now, and there is no end in sight. Even with all known fixes, proftpd is still vulnerable to remote exploitation.
When lynx calls external programs for protocols (e.g. telnet), the location is passed unchecked. This can be used to activate commandline parameters. For example, this reference [A HREF="telnet://-n.rhosts"]click me[/A] would activate the tracefile options on the telnet client, with the result, that a .rhosts in the current directory would created or overwritten.