27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

commands when they should not have that ability. Note that only users with the 'system'<br />

privileges should be able to do this. (AST-2011-006)<br />

Solution: Upgrade to Asterisk 1.4.40.1, 1.6.1.25, 1.6.2.17.3, 1.8.3.3, Business Edition C.3.6.4, or<br />

later.<br />

CVE-2011-1599<br />

Skype Detection (User-Agent)<br />

<strong>PVS</strong> ID: 5898 FAMILY: Internet Messengers RISK: LOW NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is running software that should be authorized with respect to<br />

corporate policy\n\nThe remote host is using the Skype program, a peer to peer chat and<br />

VoIP software. The reported version number is : %L<br />

Solution: Ensure that the use of this software is in accordance with organizational security policies.<br />

CVE Not available<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

Google Chrome < 11.0.696.57 Multiple Vulnerabilities<br />

<strong>PVS</strong> ID: 5899 FAMILY: Web Clients RISK: HIGH NESSUS ID:53569<br />

Description: Synopsis :\n\nThe remote host contains a web browser that is affected by a code execution<br />

vulnerability.\n\nFor your information, the observed version of Google Chrome is<br />

%L.\n\nVersions of Google Chrome earlier than 11.0.696.57 are potentially affected by<br />

multiple vulnerabilities :\n\n - A stale pointer exists in floating point handling. (61502)\n\n<br />

- It may be possible to bypass the pop-up blocker via plug-ins. (70538)\n\n - A linked-list<br />

race issue exists in database handling. Note that this issue only affects Chrome on Linux<br />

and Mac OS. (70589)\n\n - There is a lack of thread safety in MIME handling. (71586)\n\n<br />

- A bad extension with 'tabs' permission can capture local files. (72523)\n\n - It is possible<br />

to crash the browser due to bad interaction with X. Note that this issue only affects Chrome<br />

on Linux. (72910)- Multiple integer overflows exist in float rendering. (73526)\n\n - A<br />

same origin policy violation exists with blobs. (74653)\n\n - A use-after-free error exists<br />

with ruby tags and CSS. (75186)\n\n - A bad cast exists with floating select lists.<br />

(75347)\n\n - Corrupt node trees exists with mutation events. (75801)\n\n - Multiple stale<br />

pointers exist in layering code. (76001)\n\n - A race condition exists in the sandbox<br />

launcher. (76542)\n\n - An out-of-bounds read exists in SVG. (76646)\n\n - It is possible to<br />

spoof the URL bar with navigation errors and interrupted loads. (76666, 77507, 78031)\n\n<br />

- A stale pointer exists in drop-down list handling. (76966)\n\n - A stale pointer exists in<br />

height calculations. (77130)\n\n - A use-after-free error exists in WebSockets. (77346)\n\n -<br />

Multiple dangling pointers exist in file dialogs. (77349)\n\n - Multiple dangling pointers<br />

exist in DOM id map. (77463)\n\n - It is possible to spoof the URL bar with redirect and<br />

manual reload. (77786)\n\n - A use-after-free issue exists in DOM id handling. (79199)\n\n<br />

- An out-of-bounds read exists when handling multipart-encoded PDFs. (79361)\n\n -<br />

Multiple stale pointers exist with PDF forms. (79364)<br />

Solution: Upgrade to Google Chrome 11.0.696.57 or later.<br />

Family Internet Services 1603

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!