27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

CVE-2008-1024<br />

Firefox < 2.0.0.14 Javascript Garbage Collection DoS<br />

<strong>PVS</strong> ID: 4473 FAMILY: Web Clients RISK: HIGH NESSUS ID:31864<br />

Description: Synopsis :\n\nThe remote Windows host contains a web browser that may allow arbitrary<br />

code execution.\n\nThe installed version of Firefox contains a stability problem that could<br />

result in a crash during Javascript garbage collection. Although there are no examples of<br />

this extending beyond a crash, similar issues in the past have been shown to allow arbitrary<br />

code execution.<br />

Solution: Upgrade to version 2.0.0.14 or higher.<br />

CVE-2008-1380<br />

OpenOffice < 2.4 Multiple Vulnerabilities<br />

<strong>PVS</strong> ID: 4474 FAMILY: Generic RISK: HIGH NESSUS ID:31968<br />

Description: Synopsis :\n\nThe remote Windows host has a program that is affected by multiple<br />

vulnerabilities.\n\nThe version of OpenOffice installed on the remote host is reportedly<br />

affected by several issues :\n\n - Heap overflow and arbitrary code execution vulnerabilities<br />

involving ODF text documents with XForms (CVE-2007-4770/4771).\n - Heap overflow<br />

and arbitrary code execution vulnerabilities involving Quattro Pro files<br />

(CVE-2007-5745/5747).\n - Heap overflow and arbitrary code execution vulnerabilities<br />

involving EMF files (CVE-2007-5746).\n - Heap overflow and arbitrary code execution<br />

vulnerabilities involving OLE files (CVE-2008-0320).<br />

Solution: Upgrade to version 2.4 or higher.<br />

CVE-2008-0320<br />

phpBB < 3.0.1 Multiple Information Disclosure Vulnerabilities<br />

<strong>PVS</strong> ID: 4475 FAMILY: CGI RISK: HIGH NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is vulnerable to multiple attack<br />

vectors.\n\nAccording to its banner, the remote host is running a version of<br />

phpBB that is vulnerable to several flaws. An attacker exploiting these flaws<br />

would need the ability to authenticate as a valid user. Successful exploitation<br />

would allow the user to view user lists and email attachments of other users.<br />

Solution: Upgrade to version 3.0.1 or higher.<br />

CVE-2008-1766<br />

Trojan Horse Client Detection<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

<strong>PVS</strong> ID: 4476 FAMILY: Backdoors RISK: HIGH NESSUS ID:Not Available<br />

Family Internet Services 1168

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!