27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

arbitrary code execution (CVE-2008-1584).\n - There is a URL handling issue in<br />

QuickTime's handling of 'file:' URLs that may allow launching of arbitrary applications<br />

(CVE-2008-1585).<br />

Solution: Either use QuickTime's Software Update preference to upgrade to the latest version or<br />

manually upgrade to QuickTime 7.5 or later.<br />

CVE-2008-1585<br />

OpenOffice < 2.4.1 rtl_allocateMemory Integer Overflow<br />

<strong>PVS</strong> ID: 4538 FAMILY: Generic RISK: HIGH NESSUS ID:33129<br />

Description: Synopsis :\n\nThe remote Windows host has a program affected by an integer overflow<br />

vulnerability.\n\nThe version of OpenOffice installed on the remote host reportedly<br />

contains an integer overflow vulnerability in 'rtl_allocateMemory()', a custom memory<br />

allocation function used by the application. If an attacker can trick a user on the affected<br />

system, he can leverage this issue to execute arbitrary code subject to his privileges.<br />

Solution: Upgrade to OpenOffice version 2.4.1 or later.<br />

CVE-2008-2152<br />

Gordano Messaging Suite Version Detection<br />

<strong>PVS</strong> ID: 4539 FAMILY: Web Servers RISK: INFO NESSUS ID:Not Available<br />

Description: The remote host is running the Gordano Messaging Suite version: \n %L<br />

Solution: N/A<br />

CVE Not available<br />

Gallery < 2.2.4 Multiple Vulnerabilities<br />

<strong>PVS</strong> ID: 4540 FAMILY: CGI RISK: HIGH NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is Missing a critical security patch or upgrade\n\nThe<br />

remote host is running Gallery, a web-based photo album application written in PHP. The<br />

version of Gallery installed on the remote host is less than 2.2.5. The vendor has reported<br />

multiple security flaws in this version. The software is prone to a cross-site scripting flaw<br />

which could allow an attacker to execute arbitrary script code within client browsers. The<br />

software is prone to an information disclosure flaw within the 'album-select' module and<br />

the 'embed.php' script which would allow an attacker to gain access to confidential data.<br />

The software is prone to a privilege escalation flaw which would allow users the ability to<br />

gain access to confidential files or processes. Finally, the software is vulnerable to a<br />

security bypass flaw which would allow an attacker the ability to view confidential data.<br />

Solution: Upgrade to version 2.2.3 or newer<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

Family Internet Services 1186

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!