27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

even when altered by another user, which could allow that user to gain the access rights of<br />

the view. (Bug #29908)\n\n - When using a FEDERATED table, the local server can be<br />

forced to crash if the remote server returns a result with fewer columns than expected. (Bug<br />

#29801)<br />

Solution: Upgrade to version 5.0.52 or higher.<br />

CVE-2007-6304<br />

MySQL Community Server < 5.1.23 / 6.0.4 Multiple Vulnerabilities<br />

<strong>PVS</strong> ID: 4313 FAMILY: Database<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:29345<br />

Description: Synopsis :\n\nThe remote database server is affected by several issues.\n\nThe version of<br />

MySQL Server installed on the remote host reportedly is affected by the following issues<br />

:\n\n - It is possible, by creating a partitioned table using the DATA DIRECTORY and<br />

INDEX DIRECTORY options, to gain privileges on other tables having the same name as<br />

the partitioned table. (Bug #32091)\n\n - Using RENAME TABLE against a table with<br />

explicit DATA DIRECTORY and INDEX DIRECTORY options can be used to overwrite<br />

system table information. (Bug #32111).\n\n - ALTER VIEW retains the original<br />

DEFINER value, even when altered by another user, which can allow that user to gain the<br />

access rights of the view. (Bug #29908)\n\n - When using a FEDERATED table, the local<br />

server can be forced to crash if the remote server returns a result with fewer columns than<br />

expected. (Bug #29801)<br />

Solution: Upgrade to version 5.1.23, 6.0.4 or higher.<br />

CVE-2007-6304<br />

QuickTime < 7.3.1 Multiple Vulnerabilities<br />

<strong>PVS</strong> ID: 4314 FAMILY: Web Clients RISK: HIGH NESSUS ID:29698<br />

Description: Synopsis :\n\nThe remote host contains an application that is affected by multiple<br />

vulnerabilities.\n\n The version of QuickTime installed on the remote host is older than<br />

7.3.1. Such versions contain several vulnerabilities that may allow an attacker to execute<br />

arbitrary code on the remote host if a user opens a specially-crafted RTSP movie, QTL file<br />

or Flash media file with QuickTime.<br />

Solution: Upgrade to version 7.3.1 or higher.<br />

CVE-2007-6166<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

WebGUI < 7.4.18 Secondary Admin Remote Privilege Escalation<br />

<strong>PVS</strong> ID: 4315 FAMILY: CGI RISK: HIGH NESSUS ID:Not Available<br />

Family Internet Services 1123

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!