27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Description: Synopsis :\n\nThe remote host is vulnerable to multiple attack vectors.\n\nThe remote host<br />

is running ClamAV version: %L\n\nThis version of ClamAV is vulnerable to several flaws<br />

due to the way that it parses user-supplied input. It has been reported that there is a heap<br />

overflow within the 'libclamav/pe.c' file. An attacker exploiting these flaws would either<br />

crash the service or execute arbitrary code on the remote machine.<br />

Solution: Upgrade to version 0.93.0 or higher.<br />

CVE-2008-1837<br />

OTRS < 2.1.8 / 2.2.6 SOAP Interface Authentication Bypass<br />

<strong>PVS</strong> ID: 4466 FAMILY: CGI RISK: HIGH NESSUS ID:31789<br />

Description: Synopsis :\n\nThe remote web server contains a CGI script that does not properly check for<br />

authentication.\n\nThe remote host is running OTRS, a web-based ticketing request system.<br />

The version of OTRS, '%L', installed on the remote host allows a remote attacker to read<br />

and modify objects via the OTRS SOAP interface without any credentials.<br />

Solution: Upgrade to version 2.1.8 / 2.2.6 or higher.<br />

CVE-2008-1515<br />

MarketFirst Software Detection<br />

<strong>PVS</strong> ID: 4467 FAMILY: Internet Services RISK: INFO NESSUS ID:Not Available<br />

Description: The remote host is running the MarketFirst marketing application. This application is used<br />

to track downloads, users, preferences and more. The observed request to this server<br />

was:\n%P<br />

Solution: Ensure that this service is authorized according to policies and guidelines.<br />

CVE Not available<br />

MarketFirst Client Detection<br />

<strong>PVS</strong> ID: 4468 FAMILY: Web Clients RISK: INFO NESSUS ID:Not Available<br />

Description: The remote client was just observed being tracked by a MarketFirst server. The observed<br />

request was: \n %L \n\nMarketFirst is used to track downloads, users, preferences and<br />

more.<br />

Solution: N/A<br />

CVE Not available<br />

Potential SPAM Server Detection<br />

<strong>PVS</strong> ID: 4469 FAMILY: SMTP Servers<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

RISK:<br />

MEDIUM<br />

NESSUS ID:Not Available<br />

Family Internet Services 1166

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!