27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

CVE Not available<br />

Google Chrome < 10.0.648.133 Code Execution Vulnerability<br />

<strong>PVS</strong> ID: 5818 FAMILY: Web Clients RISK: HIGH NESSUS ID:52657<br />

Description: Synopsis :\n\nThe remote host contains a web browser that is affected by a code execution<br />

vulnerability.\n\nFor your information, the observed version of Google Chrome is<br />

%L.\n\nVersions of Google Chrome earlier than 10.0.648.133 are potentially affected by a<br />

memory corruption vulnerability in style handling. By tricking a user into opening a<br />

specially crafted web page, a remote unauthenticated attacker could execute arbitrary script<br />

code on the host subject to the privileges of the user running the affected application.<br />

Solution: Upgrade to Google Chrome 10.0.648.133 or later.<br />

CVE-2011-1290<br />

Facebook Chat Client Username Detection<br />

<strong>PVS</strong> ID: 5819 FAMILY: Internet Services RISK: INFO NESSUS ID:Not Available<br />

Description: The remote host is running the Facebook chat application. The logged UserID associated<br />

with this client account is : %P<br />

realtime<br />

Solution: Ensure this software meets corporate guidelines for employee use.<br />

CVE Not available<br />

Social <strong>Security</strong> Number Cleartext Transmission (Client)<br />

<strong>PVS</strong> ID: 5820 FAMILY: Data Leakage RISK: HIGH NESSUS ID:Not Available<br />

Description: The remote client sent a plaintext message which seems to contain a Social <strong>Security</strong><br />

Number. Examine the following for possible confidential data : %L<br />

realtimeonly<br />

Solution: Ensure that confidential data is encrypted while in transit<br />

CVE Not available<br />

Social <strong>Security</strong> Number Cleartext Transmission (Client)<br />

<strong>PVS</strong> ID: 5821 FAMILY: Data Leakage RISK: HIGH NESSUS ID:Not Available<br />

Description: The remote client sent a plaintext message which seems to contain a Social <strong>Security</strong><br />

Number. Examine the following for possible confidential data : %L<br />

realtimeonly<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

Family Internet Services 1580

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!