27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Solution: Microsoft has released a set of patches for Outlook Express and Windows Mail.<br />

CVE-2007-3897<br />

Cumulative <strong>Security</strong> Update for Microsoft Outlook Express and Windows Mail (941202)<br />

<strong>PVS</strong> ID: 4236 FAMILY: SMTP Clients RISK: HIGH NESSUS ID:26962<br />

Description: Arbitrary code can be executed on the remote host through the email client. The remote<br />

host is running a version of Microsoft Outlook Express that contains several security flaws<br />

that may allow an attacker to execute arbitrary code on the remote host. To exploit this<br />

flaw, an attacker would need to send a malformed email to a victim on the remote host and<br />

have him open it.<br />

Solution: Microsoft has released a set of patches for Outlook Express and Windows Mail.<br />

CVE-2007-3897<br />

SQL-Ledger < 2.6.27 Multiple Fields SQL Injection<br />

<strong>PVS</strong> ID: 4237 FAMILY: Web Servers RISK: HIGH NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a SQL injection attack.\n\nThe remote host<br />

is running SQL-Ledger, a web-based double-entry accounting system. The version of<br />

SQL-Ledger on the remote host contains a flaw in the way that it handles user-supplied<br />

data to the 'invoice quantity' and 'sort' fields. An attacker exploiting this flaw would be able<br />

to inject and run arbitrary SQL commands against the database server.<br />

Solution: Upgrade to version 2.6.27 or higher.<br />

CVE-2007-5372<br />

Firebird Database < 2.0.3.12981 'fbserver.exe' Stack Overflow<br />

<strong>PVS</strong> ID: 4238 FAMILY: Database RISK: HIGH NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a buffer overflow.\n\nThe remote host<br />

appears to be running a Firebird database server version '%L'. This version of Firebird is<br />

vulnerable to a stack overflow when processing specially malformed requests. An attacker<br />

exploiting this flaw would only need the ability to send malformed packets to the<br />

fbserver.exe process which listens on TCP port 3050 by default. Successful exploitation<br />

would result in the attacker executing arbitrary code.<br />

Solution: Upgrade to version 2.0.3.12981 or higher.<br />

CVE-2007-4992<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

IBM DB2 < 9 FixPak 3 / 8 FixPak 15 Multiple Vulnerabilities<br />

<strong>PVS</strong> ID: 4239 FAMILY: Database RISK: HIGH NESSUS ID:25905<br />

Family Internet Services 1102

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!