27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

CVE Not available<br />

Client ZIP Download Detection<br />

<strong>PVS</strong> ID: 5352 FAMILY: Web Clients RISK: INFO NESSUS ID:Not Available<br />

Description: The remote client was just observed download the following zip file: \n %L<br />

Solution: Ensure that this compressed file is in alignment with existing policies and guidelines<br />

CVE Not available<br />

Mozilla Thunderbird < 2.0.0.23 Certificate Authority (CA) Common Null Byte Handling SSL MiTM<br />

Weakness<br />

<strong>PVS</strong> ID: 5353 FAMILY: SMTP Clients<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:40664<br />

Description: Synopsis : \n\nThe remote host contains a mail client that is affected by a security bypass<br />

vulnerability.\n\nThe installed version of Mozilla Thunderbird is earlier than 2.0.0.23. Such<br />

versions are potentially affected by the following security issue : \n\n - The client can be<br />

fooled into trusting a malicious SSL server certificate with a null character in the host<br />

name. (MFSA 2009-42)\n\nFor your information, the observed version of Thunderbird is:<br />

\n %L<br />

Solution: Upgrade to Thunderbird 2.0.0.23 or later.<br />

CVE-2009-2408<br />

Mozilla Thunderbird < 3.0.1 Multiple Vulnerabilities<br />

<strong>PVS</strong> ID: 5354 FAMILY: SMTP Clients RISK: HIGH NESSUS ID:44111<br />

Description: Synopsis : \n\nThe remote host contains a mail client that is affected by multiple<br />

vulnerabilities.\n\nThe installed version of Mozilla Thunderbird is earlier than 3.0.1. Such<br />

versions are potentially affected by the following security issues : \n\n - Multiple crashes<br />

can result in arbitrary code execution. (MFSA 2009-65)\n\n - Multiple vulnerabilities in<br />

'liboggplay' can lead to arbitrary code execution. (MFSA 2009-66)\n\n - An integer<br />

overflow in the 'Theora' video library can lead to a crash or the execution of arbitrary code.<br />

(MFSA 2009-67)\n\nFor your information, the observed version of Thunderbird is: \n %L<br />

Solution: Upgrade to Mozilla Thunderbird 3.0.1 or later.<br />

CVE-2009-3982<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

Mozilla Thunderbird < 3.0.2 Multiple Vulnerabilities<br />

<strong>PVS</strong> ID: 5355 FAMILY: SMTP Clients RISK: HIGH NESSUS ID:44961<br />

Family Internet Services 1434

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!