27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Description: Synopsis : \n\nThe remote host contains an application that is vulnerable to multiple attack<br />

vectors\n\nThe remote host contains VLC player, a multi-media application. For your<br />

information, the observed version of VLC is : \n %L .\n\nVersions of VLC media player<br />

earlier than 1.1.11 are potentially affected by multiple vulnerabilities : \n\n - A buffer<br />

overflow vulnerability exists in the Read Media file parser. (SA-1105)\n\n - A heap<br />

overflow vulnerability exists in the AVI file parser. (SA-1106)<br />

Solution: Upgrade to VLC Media Player version 1.1.11 or later.<br />

CVE-2011-2588<br />

Opera < 11.10 Multiple Vulnerabilities<br />

<strong>PVS</strong> ID: 5988 FAMILY: Web Clients RISK: HIGH NESSUS ID:55506<br />

Description: Synopsis : \n\nThe remote host has a web browser that is vulnerable to multiple attack<br />

vectors.\n\nThe remote host is running the Opera web browser. For your information, the<br />

observed version of Opera is : \n %L .\n\nVersions of Opera earlier than 11.10 are<br />

potentially affected by multiple vulnerabilities : - An unspecified vulnerability allows<br />

remote attackers to hijack searches and customizations using unspecified third-party<br />

applications. (CVE-2011-2634)\n\n - Several errors exist that can cause application crashes.<br />

Affected items or functionalities are the handling of the CSS pseudo-class ': hover' if used<br />

with transforms on a floated element, unspecified web content, and the handling of an<br />

embedded Java applet with empty parameters. (CVE-2011-2635, CVE-2011-2636,<br />

CVE-2011-2637, CVE-2011-2638, CVE-2011-2640)\n\n - An error in the handling of<br />

hidden animated GIF images can cause a denial of service through CPU consumption as<br />

image repaints are triggered. (CVE-2011-2639)<br />

Solution: Upgrade to Opera 11.10 or later.<br />

CVE-2011-2640<br />

Symantec Web Gateway Detection<br />

<strong>PVS</strong> ID: 5989 FAMILY: CGI RISK: INFO NESSUS ID:55627<br />

Description: Synopsis :\n\nThe remote host is a web security appliance.\n\nThe remote host is running<br />

Symantec Web Gateway, a web security gateway appliance.<br />

Solution: N/A<br />

CVE Not available<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

Symantec Web Gateway login.php Blind SQL Injection (SYM11-001)<br />

<strong>PVS</strong> ID: 5990 FAMILY: CGI RISK: HIGH NESSUS ID:55628<br />

Description: Synopsis : \n\nThe web security application running on the remote host has a SQL injection<br />

vulnerability.\n\nFor your information, the observed version of Symantec Web Gateway<br />

installed on the remote host is : \n %L \n\nVersions of Symantec Web Gateway 4.5 earlier<br />

than 4.5.0.376 are potentially affected by a SQL injection vulnerability. Input to the<br />

Family Internet Services 1631

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!