27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

PHP 5.3.x < 5.3.15 Multiple Vulnerabilities<br />

<strong>PVS</strong> ID: 6556 FAMILY: Web Servers RISK: HIGH NESSUS ID:60085<br />

Description: Synopsis :\n\nThe remote web server uses a version of PHP that is affected by an multiple<br />

vulnerabilities.\n\nFor your information, the version of PHP installed on the remote host is<br />

:\n %L \n\nPHP versions 5.3.x earlier than 5.3.15 are affected by the following<br />

vulnerabilities.\n\n - - An unspecified overflow vulnerability exists in the function<br />

'_php_stream_scandir' in the file 'main/streams/streams.c'. (CVE-2012-2688)\n\n - An<br />

unspecified error exists that can allow the 'open_basedir' constraint to be bypassed.<br />

(CVE-2012-3365)<br />

Solution: Upgrade to PHP version 5.3.15 or later.<br />

CVE-2012-3365<br />

Opendrive Login Detection<br />

<strong>PVS</strong> ID: 6557 FAMILY: Internet Services RISK: INFO NESSUS ID:Not Available<br />

Description: The remote client has just logged into the opendrive.com HTTP interface. Opendrive is a<br />

'cloud' application which allows users to store files via an online service. The logged<br />

UserID was : %L<br />

Solution: Ensure that such usage is in aligment with Corporate policy<br />

CVE Not available<br />

Opendrive File Upload Detection<br />

<strong>PVS</strong> ID: 6558 FAMILY: Internet Services RISK: INFO NESSUS ID:Not Available<br />

Description: The remote client has just logged into the opendrive.com HTTP interface. Opendrive is a<br />

'cloud' application which allows users to store files via an online service. The user has just<br />

uploaded a file to the online service.<br />

realtimeonly<br />

Solution: Ensure that such usage is in aligment with Corporate policy<br />

Mozilla Firefox 14.x <<br />

CVE Not available<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

<strong>PVS</strong> ID: 6559 FAMILY: Web Clients RISK: HIGH NESSUS ID:61715<br />

Description: Synopsis :\n\nThe remote host has a web browser installed that is vulnerable to multiple<br />

vulnerabilities.\n\nFor your information, the observed version of Firefox is : \n %L<br />

\n\nVersions of Firefox 14.x are potentially affected by the following security issues :\n\n -<br />

An error exists related to 'Object.defineProperty' and the location object and can allow<br />

cross-site scripting attacks. (CVE-2012-1956)\n\n - Unspecified memory safety issues<br />

Family Internet Services 1793

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!