27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Several unspecified memory corruption errors exist that could lead to code execution.<br />

(CVE-2011-2445, CVE-2011-2451, CVE-2011-2452, CVE-2011-2453, CVE-2011-2454,<br />

CVE-2011-2455, CVE-2011-2459, CVE-2011-2460)\n\n - An unspecified heap corruption<br />

error exists that could lead to code execution. (CVE-2011-2450)\n\n - An unspecified<br />

buffer overflow error exists that could lead to code execution. (CVE-2011-2456)\n\n - An<br />

unspecified stack overflow error exists that could lead to code execution.<br />

(CVE-2011-2457)\n\n - An unspecified error related to Internet Explorer can allow<br />

cross-domain policy violations. (CVE-2011-2458)<br />

Solution: Upgrade to Flash Player 10.3.183.11, 11.1.102.55 or later.<br />

CVE-2011-2460<br />

iTunes < 10.5.1 Update Authenticity Verification Weakness<br />

<strong>PVS</strong> ID: 6098 FAMILY: Web Clients RISK: HIGH NESSUS ID:56873<br />

Description: Synopsis :\n\nThe remote host contains an application that is susceptible to a<br />

man-in-the-middle attack.\n\nThe remote host has iTunes installed, a popular media player<br />

for Windows and Mac OS. For your information, the observed version of iTunes is<br />

:\n%L.\n\nVersions of iTunes earlier than 10.5.1 use an unsecured HTTP connection when<br />

checking for or retrieving software updates, which could allow a man-in-the-middle<br />

attacker to provide a Trojan horse update that appears to originate from Apple.<br />

Solution: Upgrade to iTunes 10.5.1 or later.<br />

CVE-2008-3434<br />

DB2 9.7 < Fix Pack 5 Local Denial of Service Vulnerability<br />

<strong>PVS</strong> ID: 6099 FAMILY: Database RISK: LOW NESSUS ID:56928<br />

Description: Synopsis :\n\nThe remote database server is vulnerable to a denial of service attack.\n\nFor<br />

your information, the observed version of IBM DB2 is : \n %L \n\nVersions of IBM DB2<br />

9.7 earlier than Fix Pack 5 are potentially affected by a local denial of service vulnerability.<br />

On Unix and Unix-like systems with both the Self Tuning Memory manager (STMM)<br />

feature enabled and the 'DATABASE_MEMORY' option set to 'AUTOMATIC', local users<br />

are able to carry out denial of service attacks via unknown vectors.<br />

Solution: Disable automatic tuning of 'DATABASE_MEMORY' or upgrade to IBM DB2 9.7 Fix<br />

Pack 5 or later.<br />

CVE-2011-1373<br />

Sony Blu-Ray Player Detection<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

<strong>PVS</strong> ID: 6100 FAMILY: Internet Services RISK: INFO NESSUS ID:Not Available<br />

Family Internet Services 1665

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!