27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Solution: Upgrade to Android 2.3.6 or later.<br />

CVE-2011-4276<br />

PCAnywhere Detection<br />

<strong>PVS</strong> ID: 6298 FAMILY: Generic RISK: INFO NESSUS ID:Not Available<br />

Description: The remote host is running PCAnywhere, an application that allows remote users to<br />

connect to a Windows desktop and work remotely.<br />

Solution: Ensure that you are running the latest version of PCAnywhere.<br />

CVE Not available<br />

Samba 3.6.x < 3.6.3 Denial of Service<br />

<strong>PVS</strong> ID: 6299 FAMILY: Samba<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:57752<br />

Description: Synopsis :\n\nThe remote Samba server is affected by a denial of service<br />

vulnerability.\n\nFor your information, the observed version of Samba is :\n %L<br />

\n\nAccording to its banner, the version of Samba 3.6.x running on the remote host is<br />

earlier than 3.6.3. Errors exist in the files 'source3/lib/substitute.c' and<br />

'source3/smbd/server.c' that leak small amounts of memory when processing every<br />

connection attempt.\n\nAn attacker can continually make connections to the server and<br />

cause a denial of service attack against the affected smbd service.<br />

Solution: Either apply one of the patches referenced in the project's advisory or upgrade to 3.6.3 or<br />

later.<br />

CVE-2012-0817<br />

OpenSSH < 5.7 Multiple Vulnerabilities<br />

<strong>PVS</strong> ID: 6300 FAMILY: SSH<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

RISK:<br />

MEDIUM<br />

NESSUS ID:44081<br />

Description: Synopsis :\n\nThe remote SSH service may be affected by multiple vulnerabilities.\n\nFor<br />

your information, the observed version of OpenSSH installed on the remote host is : \n %L<br />

\n\nVersions of OpenSSH server before 5.7 may be affected by the following<br />

vulnerabilities :\n\n - A security bypass vulnerability because OpenSSH does not properly<br />

validate the public parameters in the J-PAKE protocol. This could allow an attacker to<br />

authenticate without the shared secret. Note that this issue is only exploitable when<br />

OpenSSH is built with J-PAKE support, which is currently experimental and disabled by<br />

default. (CVE-2010-4478)\n\n - The auth_parse options function in auth-options.c in sshd<br />

provides debug messages containing authorized_keys command options, which allows<br />

remote authenticated users to obtain potentially sensitive information by reading these<br />

messages. (CVE-2012-0841)<br />

Solution: Upgrade to OpenSSH version 5.7 or later.<br />

Family Internet Services 1719

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!