27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

CVE Not available<br />

BlackBerry Enterprise Server < 4.1.6 PDF Processing Arbitrary Code Execution<br />

<strong>PVS</strong> ID: 4590 FAMILY: Web Servers RISK: HIGH NESSUS ID:33550<br />

Description: Synopsis :\n\nThe remote Windows host has an application that is affected by a code<br />

execution vulnerability\n\nThe version of BlackBerry Enterprise Server on the remote host<br />

reportedly contains a vulnerability in the PDF distiller component of the BlackBerry<br />

Attachment Service. A remote attacker may be able to leverage this issue to execute<br />

arbitrary code on the affected host subject to the privileges under which the application<br />

runs, generally 'Administrator', by sending an email message with a specially crafted PDF<br />

file and having that opened for viewing on a BlackBerry smartphone.<br />

Solution: Either upgrade to BlackBerry Enterprise Server software version 4.1 Service Pack 6 (4.1.6),<br />

apply an appropriate interim security software update, or prevent the BlackBerry<br />

Attachment Service from processing PDF files.<br />

CVE Not available<br />

Firefox < 3.0.1 Multiple Vulnerabilities<br />

<strong>PVS</strong> ID: 4591 FAMILY: Web Clients RISK: HIGH NESSUS ID:33522<br />

Description: Synopsis :\n\nThe remote Windows host contains a web browser that is affected by<br />

multiple vulnerabilities.\n\nThe installed version of Firefox is affected by various security<br />

issues :\n\n - By creating a very large number of references to a common CSS object, an<br />

attacker can overflow the CSS reference counter, causing a crash when the browser<br />

attempts to free the CSS object while still in use and allowing for arbitrary code execution<br />

(MFSA 2008-34).\n - If Firefox is not already running, passing it a command-line URI with<br />

pipe ('|') symbols will open multiple tabs, which could be used to launch 'chrome:i' URIs<br />

from the command-line or to pass URIs to Firefox that would normally be handled by a<br />

vector application (MFSA 2008-35).<br />

Solution: Upgrade to version 3.0.1 or higher.<br />

CVE-2008-2933<br />

F-PROT Antivirus Version Detection<br />

<strong>PVS</strong> ID: 4592 FAMILY: Web Clients RISK: INFO NESSUS ID:Not Available<br />

Description: The remote host is running F-PROT Antivirus version: \n %L<br />

Solution: N/A<br />

CVE Not available<br />

F-PROT Attachment Handling DoS<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

Family Internet Services 1201

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!