27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

the application to crash. (CVE-2011-2367, CVE-2011-2368)\n\n - HTML-encoded entities<br />

are improperly decoded when displayed inside SVG elements which could lead to<br />

cross-site scripting attacks. (CVE-2011-2369)\n\n - It is possible for a non-whitelisted site<br />

to trigger an install dialog for add-ons and themes. (CVE-2011-2370)<br />

Solution: Upgrade to Firefox 5.0 or later.<br />

CVE-2011-2605<br />

Mozilla Thunderbird 3.1.x < 3.1.11 Multiple Vulnerabilities<br />

<strong>PVS</strong> ID: 5966 FAMILY: SMTP Clients RISK: HIGH NESSUS ID:55289<br />

Description: Synopsis :\n\nThe remote host has a web browser installed that is vulnerable to multiple<br />

attack vectors.\n\nFor your information, the observed version of Thunderbird is<br />

:%L.\n\nVersions of Thunderbird 3.1.x earlier than 3.1.11 are potentially affected by<br />

multiple vulnerabilities :\n\n - Multiple memory safety issues can lead to application<br />

crashes and possibly remote code execution. (CVE-2011-2374, CVE-2011-2376,<br />

CVE-2011-2364, CVE-2011-2365, CVE-2011-2605)\n\n - A use-after-free issue when<br />

viewing XUL documents with scripts disabled could lead to code execution.<br />

(CVE-2011-2373)\n\n - A memory corruption issue due to multipart/x-mixed-replace<br />

images could lead to memory corruption. (CVE-2011-2377)\n\n - When a JavaScript Array<br />

object has its length set to an extremely large value, the iteration of array elements that<br />

occurs when its reduceRight method is called could result in code execution due to an<br />

invalid index value being used. (CVE-2011-2371)\n\n - Multiple dangling pointer<br />

vulnerabilities could lead to code execution. (CVE-2011-0083, CVE-2011-2363,<br />

CVE-2011-0085)\n\n - An error in the way cookies are handled could lead to information<br />

disclosure. (CVE-2011-2362)<br />

Solution: Upgrade to Thunderbird 3.1.11 or later.<br />

CVE-2011-2605<br />

Flash Player < 10.3.181.26 Code Execution Vulnerability (APSB11-18)<br />

<strong>PVS</strong> ID: 5967 FAMILY: Web Clients RISK: HIGH NESSUS ID:55141<br />

Description: Synopsis : \n\nThe remote host contains a browser plug-in that is affected by a memory<br />

corruption vulnerability.\n\nThe remote host has Adobe Flash Player installed. For your<br />

information, the observed version of Adobe Flash Player is : \n %L .\n\nVersions of Flash<br />

Player earlier than 10.3.181.26 are potentially affected by a memory corruption<br />

vulnerability that could allow an attacker to execute arbitrary code subject to the privileges<br />

of the user running the affected application. This issue is reportedly being exploited in the<br />

wild in targeted attacks as of June 2011.<br />

Solution: Upgrade to Flash Player 10.3.181.26 or later.<br />

CVE-2011-2110<br />

Mac OS X 10.6 < 10.6.8 Multiple Vulnerabilities<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

Family Internet Services 1624

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!