MidnightBSD

Advisories for niels_provos

CVE-2004-2095 MEDIUM

Honeyd before 0.8 replies to TCP packets with the SYN and RST flags set, which allows remote attackers to identify IP addresses that are being simulated by Honeyd.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
niels_provos honeyd 0.5
niels_provos honeyd 0.7a
niels_provos honeyd 0.6a
niels_provos honeyd 0.7
niels_provos honeyd 0.6
CVE-2006-0752 MEDIUM

Niels Provos Honeyd before 1.5 replies to certain illegal IP packet fragments that other IP stack implementations would drop, which allows remote attackers to identify IP addresses that are being simulated using honeyd.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
niels_provos honeyd 0.5
niels_provos honeyd 0.7a
niels_provos honeyd 0.6a
niels_provos honeyd 0.8a
niels_provos honeyd 0.8b
niels_provos honeyd 1.5a
niels_provos honeyd 0.7
niels_provos honeyd 0.8
niels_provos honeyd 1.0
niels_provos honeyd 0.6
CVE-2006-4292 MEDIUM

Unspecified vulnerability in Niels Provos Honeyd before 1.5b allows remote attackers to cause a denial of service (application crash) via certain Address Resolution Protocol (ARP) packets.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
niels_provos honeyd 1.5a
niels_provos honeyd 1.5
niels_provos honeyd 1.0
CVE-2007-1030 HIGH

Niels Provos libevent 1.2 and 1.2a allows remote attackers to cause a denial of service (infinite loop) via a DNS response containing a label pointer that references its own offset.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
niels_provos libevent 1.2a
niels_provos libevent 1.2
CVE-2009-0343 HIGH

Niels Provos Systrace 1.6f and earlier on the x86_64 Linux platform allows local users to bypass intended access restrictions by making a 32-bit syscall with a syscall number that corresponds to a policy-compliant 64-bit syscall, related to race conditions that occur in monitoring 64-bit processes.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
niels_provos systrace 1.3
niels_provos systrace 1.6c
niels_provos systrace *
niels_provos systrace 1.6b
niels_provos systrace 1.6a
niels_provos systrace 1.4
niels_provos systrace 1.6
niels_provos systrace 1.6d
niels_provos systrace 1.2
niels_provos systrace 1.5
niels_provos systrace 1.1