27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

security bypass vulnerability that can be exploited by an attacker if the victim can be<br />

tricked into setting a new home page by dragging a specially crafted link to the 'home'<br />

button URL, which will set the user's home page to a 'javascript:' URL.<br />

(CVE-2012-0458)\n\n - An information disclosure vulnerability due to an out of bounds<br />

read in SVG filters. (CVE-2012-0456)\n\n - A cross-site scripting vulnerability that can be<br />

triggered by dragging and dropping 'javascript:' links onto a frame. (CVE-2012-0455)\n\n -<br />

'window.fullScreen' is writeable by untrusted content, allowing attackers to perform UI<br />

spoofing attacks. (CVE-2012-0460)<br />

Solution: Upgrade to SeaMonkey 2.8 or later.<br />

CVE-2012-0464<br />

VLC Media Player < 2.0.1 Multiple Code Execution Vulnerabilities<br />

<strong>PVS</strong> ID: 6355 FAMILY: Web Clients RISK: HIGH NESSUS ID:58416<br />

Description: Synopsis :\n\nThe remote host contains an application that is vulnerable to multiple attack<br />

vectors\n\nThe remote host contains VLC player, a multi-media application. For your<br />

information, the observed version of VLC is : \n %L .\n\nVersions of VLC media player<br />

earlier than 2.0.1 are potentially affected by multiple vulnerabilities :\n\n - A stack<br />

overflow exists in MMS support. (CVE-2012-1775)\n\n - Multiple heap overflows exist in<br />

Real RTSP support. (CVE-2012-1776)<br />

Solution: Upgrade to VLC Media Player version 2.0.1 or later.<br />

CVE-2012-1776<br />

Google Chrome < 17.0.963.83 Multiple Vulnerabilities<br />

<strong>PVS</strong> ID: 6356 FAMILY: Web Clients RISK: HIGH NESSUS ID:58434<br />

Description: Synopsis :\n\nThe remote host contains a web browser that is affected by multiple<br />

vulnerabilities.\n\nFor your information, the observed version of Google Chrome is :\n %L<br />

\n\nVersions of Google Chrome earlier than 17.0.963.83 are potentially affected by the<br />

following vulnerabilities :\n\n - An unspecified integer issue exists in libpng.<br />

(CVE-2011-3045)\n\n - Use-after-free errors exist related to 'first-letter' handling, CSS<br />

cross-fade handling and block splitting. (CVE-2011-3050, CVE_2011-3051,<br />

CVE-2011-3053)\n\n - A memory corruption error exists related to WebGL canvas<br />

handling. (CVE-2011-3052)\n\n - An error exists related to webui privilege isolation.<br />

(CVE-2011-3054)\n\n - Installation of unpacked extensions does not use the application's<br />

native user interface for prompts. (CVE-2011-3055)\n\n - A cross-origin violation is<br />

possible with 'magic iframe'. (CVE-2011-3056)\n\n - The v8 JavaScript engine can allow<br />

invalid reads to take place. (CVE-2011-3057)<br />

Solution: Upgrade to Google Chrome 17.0.963.83 or later.<br />

CVE-2011-3056<br />

E-mail Client Detection<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

Family Internet Services 1739

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!