27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Description: Synopsis : \n\nThe remote host is vulnerable to multiple attack vectors.\n\nAccording to its<br />

version, the clamd antivirus daemon on the remote host is earlier than 0.95.1. Such versions<br />

are affected by multiple vulnerabilities : \n\n- ClamAV might crash while scanning certain<br />

malicious files packed with UPack. (Bug #1552)\n\n- ClamAV might crash while using<br />

'cli_url_canon'. (Bug #1553)\n\nThe current version of ClamAV on the remote host is: \n<br />

%L \n<br />

Solution: Upgrade to version 0.95.1 or higher.<br />

CVE-2009-1372<br />

Microsoft TMG Proxy Detection<br />

<strong>PVS</strong> ID: 4987 FAMILY: Web Servers RISK: INFO NESSUS ID:Not Available<br />

Description: The remote host is a proxy server running the Microsoft Threat Management Gateway<br />

(TMG) software.<br />

Solution: N/A<br />

CVE Not available<br />

SeaMonkey < 1.1.16 XSL Transformation Overflow DoS<br />

<strong>PVS</strong> ID: 4988 FAMILY: Web Clients RISK: HIGH NESSUS ID:36130<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a buffer overflow.\n\nThe installed version<br />

of SeaMonkey is earlier than 1.1.16. An XSL transformation vulnerability in such versions<br />

can be leveraged with a specially crafted stylesheet to crash the browser or to execute<br />

arbitrary code.<br />

Solution: Upgrade to version 1.1.16 or higher.<br />

CVE-2009-1169<br />

Policy - .divx File Detection<br />

<strong>PVS</strong> ID: 4989 FAMILY: CGI RISK: INFO NESSUS ID:Not Available<br />

Description: The remote web server is hosting .divx audio/video files. As an example, consider the<br />

following file %P\nThe webmaster should make sure that they are in compliance with<br />

corporate policies and guidelines.<br />

Solution: N/A<br />

CVE Not available<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

IBM WebSphere Application Server < 6.0.2.33 Multiple Vulnerabilities<br />

<strong>PVS</strong> ID: 4990 FAMILY: Web Servers RISK: HIGH NESSUS ID:36132<br />

Family Internet Services 1318

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!