27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

it may cause the name server process to crash.<br />

Solution: Upgrade to BIND 9.8.0-P3 or later.<br />

CVE-2011-2465<br />

ISC BIND 9 Unspecified Packet Processing Remote DoS<br />

<strong>PVS</strong> ID: 5982 FAMILY: DNS Servers<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:55534<br />

Description: Synopsis : \n\nThe remote DNS server is vulnerable to a denial of service attack.\n\nThe<br />

remote host is running Bind, a popular name server. For your information, the observed<br />

version of Bind is : \n %L \n\nVersions of BIND 9.6 earlier than 9.6-ESV-R4-P3, 9.7<br />

earlier than 9.7.3-P3, and 9.8 earlier than 9.8.0-P4 are potentially affected by a denial of<br />

service vulnerability. If an attacker sends a specially crafted request to a BIND server it<br />

may cause the name server process to crash.<br />

Solution: Upgrade to BIND 9.6-ESV-R4-P3, 9.7.3-P3, 9.8.0-P4, or later.<br />

CVE-2011-2464<br />

HP Intelligent Management Center User Access Manager < 5.0 E0101P03 Code Execution<br />

Vulnerability<br />

<strong>PVS</strong> ID: 5983 FAMILY: Generic RISK: HIGH NESSUS ID:55577<br />

Description: Synopsis : \n\nThe remote host has an application installed that is vulnerable to a code<br />

execution attack.\n\nFor your information, the version of HP Intelligent Management<br />

Center installed on the remote host is : \n %L \n\nVersions of HP Intelligent Management<br />

Center User Access Manager earlier than 5.0 E0101P03 are potentially affected by a code<br />

execution vulnerability in the 'iNOdeMngChecker.exe' component which listens by default<br />

on TCP port 9090 because the application fails to validate user supplied data when<br />

handling a '0x0A0BF007' packet type. A remote unauthenticated attacker, exploiting this<br />

flaw, could potentially execute arbitrary code on the remote host subject to the privileges of<br />

the user running the affected application.<br />

Solution: Upgrade to HP Intelligent Management Center User Access Manager 5.0 E0101P03 or<br />

later.<br />

CVE-2011-1867<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

HP Intelligent Management Center Endpoint Admission Defense < 5.0 E0101P03 Code Execution<br />

Vulnerability<br />

<strong>PVS</strong> ID: 5984 FAMILY: Generic RISK: HIGH NESSUS ID:55577<br />

Description: Synopsis : \n\nThe remote host has an application installed that is vulnerable to a code<br />

execution attack.\n\nFor your information, the version of HP Intelligent Management<br />

Center installed on the remote host is : \n %L \n\nVersions of HP Intelligent Management<br />

Center Endpoint Admission Defense earlier than 5.0 E0101P03 are potentially affected by a<br />

Family Internet Services 1629

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!