27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

for several prominent public websites.\n\nIf an attacker can trick someone into using the<br />

affected browser and visiting a malicious site using one of the fraudulent certificates, he<br />

may be able to fool that user into believing the site is a legitimate one. In turn, the user<br />

could send credentials to the malicious site or download and install applications.<br />

Solution: Upgrade to SeaMonkey 2.0.13 or later.<br />

CVE Not available<br />

Google Chrome < 10.0.648.204 Multiple Vulnerabilities<br />

<strong>PVS</strong> ID: 5845 FAMILY: Web Clients RISK: HIGH NESSUS ID:52975<br />

Description: Synopsis :\n\nThe remote host contains a web browser that is affected by a code execution<br />

vulnerability.\n\nFor your information, the observed version of Google Chrome is<br />

%L.\n\nVersions of Google Chrome earlier than 10.0.648.204 are potentially affected by<br />

multiple vulnerabilities :\n\n - A buffer error exists in string handling functions.<br />

(72517)\n\n - A use-after-free error exists in the process for loading frames. (73216)\n\n - A<br />

use-after-free error exists in the processing of HTML Collections. (73595)\n\n - An error<br />

exists in the processing of CSS which leaves stale pointers behind. (74562)\n\n - An<br />

unspecified error allows DOM tree corruption related to broken node-hierarchy.<br />

(74991)\n\n - An error exists in the processing of SVG text which leaves stale pointers<br />

behind. (75170)<br />

Solution: Upgrade to Google Chrome 10.0.648.204 or later.<br />

CVE-2011-1296<br />

VLC Media Player < 1.1.8 Multiple Buffer Overflows<br />

<strong>PVS</strong> ID: 5846 FAMILY: Web Clients RISK: HIGH NESSUS ID:52976<br />

Description: Synopsis :\n\nThe remote host contains an application that allows arbitrary code<br />

execution.\n\nThe remote host contains VLC player, a multi-media application. For your<br />

information, the observed version of VLC is %L.\n\nVersions of VLC media player earlier<br />

than 1.1.8 are potentially affected by buffer overflow vulnerabilities when handling<br />

specially crafted AMV and NSV files, which could result in arbitrary code execution.<br />

Solution: Upgrade to VLC Media Player version 1.1.8 or later.<br />

CVE-2010-3276<br />

Generic Credit Card Signature Detection<br />

<strong>PVS</strong> ID: 5847 FAMILY: Data Leakage RISK: INFO NESSUS ID:Not Available<br />

Description: Generic credit card sigs<br />

Solution: N/A<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

Family Internet Services 1588

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!