27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Description: Synopsis :\n\nThe remote Samba server is affected by multiple<br />

vulnerabilities.\n\nAccording to its banner, the version of the Samba server installed on the<br />

remote host ('%L') is affected by multiple buffer overflow and remote command injection<br />

vulnerabilities that can be exploited remotely, as well as a local privilege escalation bug.<br />

The reported version number of Samba is\n%L<br />

Solution: Upgrade to version 3.0.25 or higher.<br />

CVE-2007-2447<br />

BitTorrent Server Detection<br />

<strong>PVS</strong> ID: 3991 FAMILY: Peer-To-Peer File Sharing<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is running software that should be authorized with respect to<br />

corporate policy.\n\nThe remote host is running a BitTorrent server.\nBitTorrent is a P2P<br />

application that allows users to quickly download files from multiple locations.<br />

Solution: Ensure that BitTorrent is allowed with respect to corporate policies and guidelines.<br />

CVE Not available<br />

Resin < 3.1.1 Directory Traversal Vulnerability (2)<br />

<strong>PVS</strong> ID: 3992 FAMILY: Web Servers<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:25241<br />

Description: Synopsis :\n\nThe remote web server is prone to a directory traversal attack. \n\nThe<br />

remote host is running Resin, an application server. The installation of Resin on the remote<br />

host allows an unauthenticated remote attacker to gain access to the web-inf directories, or<br />

any known subdirectories, on the affected Windows host, which may lead to a loss of<br />

confidentiality.<br />

Solution: Upgrade to version 3.1.1 or higher.<br />

CVE-2007-2440<br />

MySQL < 5.1.18 Multiple Vulnerabilities<br />

<strong>PVS</strong> ID: 3993 FAMILY: Database<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

RISK:<br />

MEDIUM<br />

NESSUS ID:25242<br />

Description: Synopsis :\n\nThe remote database server is affected by multiple vulnerabilities.\n\nThe<br />

version of MySQL installed on the remote host reportedly is affected by three issues :\n\n-<br />

A user can rename a table without having DROP privileges.\n\n-If a stored routine is<br />

declared as 'SQL SECURITY INVOKER', a user may be able to gain privileges by<br />

invoking that routine.\n\n-A user with only ALTER privileges on a partitioned table can<br />

discover information about the table that should require SELECT privileges.<br />

Family Internet Services 1035

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!