27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

CVE-2008-6976<br />

Google Chrome Version Detection<br />

<strong>PVS</strong> ID: 4645 FAMILY: Web Clients RISK: INFO NESSUS ID:Not Available<br />

Description: The remote host is running the Google Chrome web browser version: %L<br />

Solution: N/A<br />

CVE Not available<br />

Simple Machines Forum < 1.1.6 Random Number Generator Credentials Disclosure<br />

<strong>PVS</strong> ID: 4646 FAMILY: CGI RISK: HIGH NESSUS ID:Not Available<br />

Description: Synopsis : \n\nThe remote host is is vulnerable to a security-bypass flaw.\n\nThe remote<br />

host is running the Simple Machines Forum (SMF), a web forum. This version of SMF is<br />

vulnerable to a flaw where it will leak the state of the random number generator. As<br />

authentication materials are created using the random number generator, an attacker can use<br />

the leaked state to determine authentication codes of other users. Note that this<br />

vulnerability only affects the Windows versions of SMF that use a simple, linear,<br />

feed-forward design for generating random numbers. The reported version of SMF is: \n<br />

%L \n<br />

Solution: Upgrade to version 1.1.6 or higher.<br />

CVE-2008-6971<br />

Novell iPrint Client nipplib.dll IppCreateServerRef Function Buffer Overflow<br />

<strong>PVS</strong> ID: 4647 FAMILY: Web Clients RISK: HIGH NESSUS ID:34085<br />

Description: Synopsis :\n\nThe remote Windows host has an application that is affected by a buffer<br />

overflow vulnerability.\n\nThe installed version of Novell iPrint Client is affected by a<br />

buffer overflow vulnerability. By passing very long arguments to either<br />

'GetPrinterURLList()', 'GetPrinterURLList2()', or 'GetFileList2()' functions available in<br />

ActiveX control 'ienipp.ocx', it may be possible to cause a heap-based buffer overflow in<br />

function 'IppCreateServerRef()' provided by 'nipplib.dll'. Successful exploitation of this<br />

issue may result in arbitrary code execution on the remote system.<br />

Solution: Upgrade to Novell iPrint Client version 5.08 or Novell iPrint Client for Windows 4.38 or<br />

higher.<br />

CVE-2008-2436<br />

WordPress < 2.6.2 Administrative Password Reset<br />

<strong>PVS</strong> ID: 4648 FAMILY: CGI<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

RISK:<br />

MEDIUM<br />

NESSUS ID:Not Available<br />

Family Internet Services 1218

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!