27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

CVE-2008-3629<br />

MySQL Empty Binary String DoS<br />

<strong>PVS</strong> ID: 4652 FAMILY: Database<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a Denial of Service (DoS) attack.\n\nThe<br />

remote host is running MySQL database version: %L\n\nThis version of MySQL is<br />

vulnerable to a remote Denial of Service (DoS) attack when it processes empty binary<br />

strings. An attacker exploiting this flaw would need some way of injecting data into a<br />

MySQL query. Successful exploitation would result in the database crashing.<br />

Solution: Upgrade to version 5.0.66, 5.1.26, 6.0.6 or higher.<br />

CVE-2008-3963<br />

iTunes < 8.0 Multiple Vulnerabilities<br />

<strong>PVS</strong> ID: 4653 FAMILY: Web Clients RISK: HIGH NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is vulnerable to multiple attack vectors.\n\nThe remote host<br />

is running iTunes, an application for managing and listening to music media files. The<br />

version of iTunes is '%L'.\n\nThis version of iTunes is vulnerable to a several local flaws.<br />

The first involves an integer overflow and would result in the local attacker executing<br />

arbitrary code with the privileges of the iTunes program. The second flaw involves<br />

misleading firewall messages that may lead to a false sense of security.<br />

Solution: Upgrade to version 8.0 or higher.<br />

CVE-2008-3636<br />

Apple iPod Device Detection<br />

<strong>PVS</strong> ID: 4654 FAMILY: Mobile Devices RISK: INFO NESSUS ID:Not Available<br />

Description: The remote device is an Apple iPod. iPod is a multimedia hardware application that allows<br />

users to store files of various formats on the device.<br />

Solution: Ensure that such devices are authorized according to corporate policies and guidelines.<br />

CVE Not available<br />

MyBB < 1.4.1 Multiple Vulnerabilities<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

<strong>PVS</strong> ID: 4655 FAMILY: CGI RISK: HIGH NESSUS ID:Not Available<br />

Description: Synopsis : \n\nThe remote host is vulnerable to multiple attack vectors.\n\nThe version of<br />

MyBB installed on the remote host is vulnerable to a number of vulnerabilities. The<br />

application fails to properly parse and sanitize data sent to the 'misc.php', 'usercp2.php',<br />

'inc/functions_online.php', and 'moderation.php' scripts. The details of these flaws are<br />

Family Internet Services 1220

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!