27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

CVE Not available<br />

Netopia Timbuktu Detection<br />

<strong>PVS</strong> ID: 4194 FAMILY: Policy RISK: INFO NESSUS ID:Not Available<br />

Description: The remote host is running Timbuktu, a remote management software. Systems running<br />

Timbuktu can both manage and be managed remotely. Further, the software supports<br />

tunneling, which allows a host to be accessed despite firewall policies that might attempt to<br />

block it.<br />

Solution: Ensure that such software is authorized according to corporate policies and guidelines.<br />

CVE Not available<br />

ISC BIND < 8.4.7-P1 Outgoing Query Predictable DNS Query ID<br />

<strong>PVS</strong> ID: 4195 FAMILY: DNS Servers<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote DNS server is vulnerable to a cache-poisoning attack.\n\nThe<br />

remote host is running a version of BIND DNS Server prior to 8.4.7-P1. This version of<br />

BIND is vulnerable to a flaw that would allow cache poisoning. An attacker exploiting this<br />

flaw would need to be able to manipulate the vulnerable DNS server into contacting a<br />

malicious DNS server. Successful exploitation would lead to a cache-poisoning attack.<br />

Solution: BIND 8 is no longer supported by ISC. Upgrade or patch according to vendor<br />

recommendations.<br />

CVE-2007-2930<br />

Windows Live Messenger Version Detection<br />

<strong>PVS</strong> ID: 4196 FAMILY: Internet Messengers RISK: INFO NESSUS ID:Not Available<br />

Description: The remote host is running Windows Live Messenger version %L<br />

Solution: N/A<br />

CVE Not available<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

Windows Live Messenger < 8.1.0178 Video Processing Overflow<br />

<strong>PVS</strong> ID: 4197 FAMILY: Internet Messengers RISK: HIGH NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a buffer overflow.\n\nThe remote host is<br />

running Windows Live Messenger version %L. This version of Windows Live Messenger<br />

is vulnerable to a flaw in the way that it processes video messages. An attacker exploiting<br />

this flaw would need to be able to initiate a chat session with a user running a vulnerable<br />

version of the software. Successful exploitation would result in the attacker executing<br />

Family Internet Services 1090

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!