27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Description: Synopsis :\n\nThe remote host is vulnerable to multiple local flaws.\n\nThe remote<br />

host is running IBM DB2 database version %L.\nThis version is reported to be<br />

vulnerable to a number of local flaws. The most serious of these flaws involves a<br />

local buffer overflow. An attacker exploiting these flaws would need local access to<br />

the DB2 server. Successful exploitation would result in the attacker executing<br />

arbitrary code.<br />

Solution: IBM has released Fixpak 2 for version 9.1 installs. Upgrade or patch older installations<br />

according to vendor recommendations.<br />

CVE-2007-1228<br />

Firefox < 1.5.0.10 / 2.0.0.2 Multiple Vulnerabilities<br />

<strong>PVS</strong> ID: 3922 FAMILY: Web Clients RISK: HIGH NESSUS ID:24701<br />

Description: Synopsis :\n\nThe remote Windows host contains a web browser that is affected by<br />

multiple vulnerabilities.\n\nThe installed version of Firefox is affected by various security<br />

issues, some of which may lead to execution of arbitrary code on the affected host subject<br />

to the user's privileges.<br />

Solution: Upgrade to version 1.5.0.10, 2.0.0.2 or higher.<br />

CVE-2007-0996<br />

WebAPP < 0.9.9.6 Multiple Vulnerabilities<br />

<strong>PVS</strong> ID: 3923 FAMILY: CGI RISK: HIGH NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is vulnerable to multiple attack vectors.\n\nThe remote host<br />

is running WebAPP, an open-source web portal application written in Perl. There is a flaw<br />

in the remote version of this software that may allow an attacker to gain remote control of<br />

the application. The exact nature of the flaws is currently unknown. However, given the<br />

vendor's statement regarding the patches, the flaws are thought to be of a serious nature.<br />

Solution: Upgrade to version 0.9.9.6 or higher.<br />

CVE Not available<br />

Google Desktop Detection<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

<strong>PVS</strong> ID: 3924 FAMILY: Web Clients RISK: INFO NESSUS ID:24709<br />

Description: Synopsis :\n\nThe remote host has Google Desktop installed.\n\nGoogle Desktop, a search<br />

application for Windows that allows users to easily search for files on the computer, is<br />

installed on the remote host. If the 'Advanced Features' or 'Search Across Computers'<br />

options of Google Desktop are enabled, some data may be sent to Google's servers,<br />

potentially breaching confidentiality and your corporate security policy.<br />

Solution: Ensure that installing Google Desktop is authorized by your corporate policy.<br />

Family Internet Services 1016

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!