27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

CVE Not available<br />

VMWare Server Plaintext Authorization<br />

<strong>PVS</strong> ID: 4288 FAMILY: Generic<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host passes information across the network in an insecure<br />

manner.\n\nThe remote host is running VMWare server, an application that allows users to<br />

run multiple operating systems virtually. Futher, this instance of VMWare is a server<br />

application that allows remote administrator access to the VMWare console. The displayed<br />

banner is '%L'\nThis version of VMWare Server allows authentication without SSL.<br />

Sending credentials in plaintext allows passive attackers to either execute<br />

man-in-the-middle attacks or sniff the credentials while in transit.<br />

Solution: Newer versions of the VMware Authentication daemon can be configured to only accept<br />

authentication over SSL.<br />

CVE Not available<br />

LIVE555 Media Server < 2007.11.18 DoS<br />

<strong>PVS</strong> ID: 4289 FAMILY: Generic RISK: HIGH NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a Denial of Service (DoS) attack.\n\nThe<br />

remote host is running LIVE555 Media Server, a media streaming server. The version of<br />

LIVE55 installed on the remote host is vulnerable to a denial of service attack when sent a<br />

request of less than 8 bytes. An attacker exploiting this flaw would only need the ability to<br />

connect to the RTSP server via the network. Successful exploitation would result in the<br />

service crashing.<br />

Solution: Upgrade to version 2007.11.18 or higher.<br />

CVE-2007-4561<br />

Ability Mail Server < 2.61 Multiple Vulnerabilities<br />

<strong>PVS</strong> ID: 4290 FAMILY: IMAP Servers<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:28289<br />

Description: Synopsis :\n\nThe remote mail server is affected by multiple denial of service<br />

vulnerabilities.\n\n The remote host appears to be running Ability IMAP Server. According<br />

to its banner, the installed version of Ability Mail Server is affected by two issues that<br />

could cause the application to crash. One involves messages that are changed to a blank<br />

string, the other concerns IMAP4 commands with malformed number list ranges. It is not<br />

currently known whether either or both issues can be exploited without authentication.<br />

Solution: Upgrade to version 2.61 or higher.<br />

CVE-2007-6101<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

Family Internet Services 1116

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!