27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Description: The remote host is running the Sophos AV software version: %L<br />

Solution: N/A<br />

CVE Not available<br />

Apache 2.4 < 2.4.3 Multiple Vulnerabilities<br />

<strong>PVS</strong> ID: 6550 FAMILY: Web Servers<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:61644<br />

Description: Synopsis:\n\nThe remote web server is affected by multiple vulnerabilities.\n\nThe remote<br />

host is running a Apache HTTP server. For your information, the observed version of<br />

Apache is:\n %L \n\n Versions earlier than 2.4.3 are vulnerable to the following<br />

vulnerabilities :\n\n - An input validation error exists related to 'mod_negotiation',<br />

'Multiviews' and untrusted uploads that can allow cross-site scripting attacks.<br />

(CVE-2012-2687)\n\n - An error exists related to 'mod_proxy_ajp' and 'mod_proxy_http'<br />

that can allow connections to remain open. This condition can allow information disclosure<br />

when combined with specially crafted requests. (CVE-2012-3502)<br />

Solution: Upgrade to Apache version 2.4.3 or later<br />

CVE-2012-3502<br />

Opera < 12.01 Multiple Vulnerabilities<br />

<strong>PVS</strong> ID: 6551 FAMILY: Web Clients RISK: HIGH NESSUS ID:61414<br />

Description: Synopsis :\n\nThe remote host has a web browser installed that is vulnerable to multiple<br />

attack vectors.\n\nThe remote host is running the Opera web browser. For your<br />

information, the observed version of Opera is : \n %L \n\nVersions of Opera earlier than<br />

12.01 are potentially affected by multiple vulnerabilities :\n\n - An error exists in the<br />

handling of certain URLs that can lead to memory corruption and possible code execution.<br />

(1016)\n\n - Errors exist in the handling of DOM elements and certain HTML characters<br />

that can lead to cross-site scripting. (1025, 1026)\n\n - Download dialog boxes can be made<br />

small enough that users may not realize they are accepting a download and further,<br />

executing such a download. (1027)\n\n - An attacker could cause an application crash by<br />

tricking a user into connecting to a malicious site, as demonstrated by the Lenovo 'Shop<br />

Now' page. (CVE-2012-4146)<br />

Solution: Upgrade to Opera 12.01 or later.<br />

CVE-2012-4146<br />

Hulu plus search detection on the Apple iPad<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

<strong>PVS</strong> ID: 6552 FAMILY: Internet Services RISK: INFO NESSUS ID:Not Available<br />

Family Internet Services 1791

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!