27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Solution: Upgrade to EvoCam 3.6.8 or later.<br />

CVE-2010-2309<br />

Google Chrome < 5.0.375.86 Multiple Vulnerabilities<br />

<strong>PVS</strong> ID: 5584 FAMILY: Web Clients RISK: HIGH NESSUS ID:47139<br />

Description: Synopsis :\n\nThe remote host contains a web browser that is vulnerable to multiple attack<br />

vectors.\n\nFor your information, the observed version of Google Chrome installed on the<br />

remote host is : %L\n\nVersions of Google Chrome earlier than 5.0.375.86 are potentially<br />

affected by multiple vulnerabilities :\n\n - A cross-site scripting vulnerability in<br />

'application/json' responses. (Bug 38105)\n\n - A memory error in video handling. (Bug<br />

43322)\n\n - A subresource is displayed in omnibox loading. (Bug 43967)\n\n - A memory<br />

error in video handling. (Bug 45267)\n\n - A stale pointer in x509-user-cert response. (Bug<br />

46126)<br />

Solution: Upgrade to Google Chrome 5.0.375.86 or later.<br />

CVE Not available<br />

Bugzilla < 3.2.7 / 3.4.7 / 3.6.1 Multiple Vulnerabilities<br />

<strong>PVS</strong> ID: 5585 FAMILY: CGI<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:47166<br />

Description: Synopsis :\n\nThe remote web server is hosting an application that is vulnerable to multiple<br />

attack vectors.\n\nThe remote web server is hosting Bugzilla, a web-based bug tracking<br />

application. For your information, the observed version of Bugzilla is %L.\n\nVersions of<br />

Bugzilla earlier than 3.2.7, 3.4.x earlier than 3.4.7, and 3.6.x earlier than 3.6.1 are<br />

potentially affected by multiple vulnerabilities :\n\n - It is possible to determine<br />

time-tracking information for bugs through specially crafted search URLs.<br />

(CVE-2010-1204)\n\n - If '$use_suexec' is set to '1' in the localconfig file, the localconfig<br />

file's permissions were set as world-readable by checksetup.pl. (CVE-2010-0180)<br />

Solution: Upgrade to Bugzilla 3.2.7, 3.4.7, 3.6.1, or later.<br />

Web Server Detection<br />

CVE-2010-1204<br />

<strong>PVS</strong> ID: 5586 FAMILY: Web Servers RISK: NONE NESSUS ID:Not Available<br />

Description: A web server is running on this port : %L<br />

Solution: N/A<br />

realtimeonly<br />

CVE Not available<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

Family Internet Services 1499

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!