27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Description: The remote client is accessing the Cydia software packages. Cydia is an indepented<br />

third-party app distribution platform for Apple iOS. Cydia is mostly use for<br />

Jailbroken devices. The following iOS version was detected:\n %L \n<br />

Solution: Ensure that such usage is in aligment with Corporate policy<br />

CVE Not available<br />

Google Chrome < 22.0.1229.79 Multiple Vulnerabilities<br />

<strong>PVS</strong> ID: 6592 FAMILY: Web Clients RISK: HIGH NESSUS ID:62313<br />

Description: Synopsis :\n\nThe remote host contains a web browser that is affected by multiple<br />

vulnerabilities.\n\nFor your information, the observed version of Google Chrome is :\n %L<br />

\n\nVersions of Google Chrome earlier than 22.0.1229.79 are potentially affected by the<br />

following vulnerabilities :\n\n - Out-of-bounds write errors exist related to Skia and the<br />

PDF viewer. (CVE-2012-2874, CVE-2012-2883, CVE-2012-2895)\n\n - Various,<br />

unspecified errors exist related to the PDF viewer. (CVE-2012-2875)\n\n - A buffer<br />

overflow error exists related to 'SSE2' optimizations. (CVE-2012-2876)\n\n - An<br />

unspecified error exists related to extensions and modal dialogs that can allow application<br />

crashes. (CVE-2012-2877)\n\n - Use-after-free errors exist related to plugin handling,<br />

'onclick' handling, 'SVG' text references and the PDF viewer. (CVE-2012-2878,<br />

CVE-2012-2887, CVE-2012-2888, CVE-2012-2890)\n\n - An error exists related to 'DOM'<br />

topology corruption. (CVE-2012-2879)\n\n - Race conditions exist in the plugin paint<br />

buffer. (CVE-2012-2880)\n\n - 'DOM' tree corruption can occur with plugins.<br />

(CVE-2012-2881)\n\n - A pointer error exists related to 'OGG' container handling.<br />

(CVE-2012-2882)- An out-of-bounds read error exists related to Skia.<br />

(CVE-2012-2884)\n\n - The possibility of a double-free error exists related to application<br />

exit. (CVE-2012-2885)\n\n - Universal cross-site scripting issues exist related to the v8<br />

JavaScript engine bindings and frame handling. (CVE-2012-2886, CVE-2012-2889)\n\n -<br />

Address information can be leaked via inter process communication (IPC).<br />

(CVE-2012-2891)\n\n - A bypass error exists related to pop-up block.<br />

(CVE-2012-2892)\n\n - A double-free error exists related to 'XSL' transforms.<br />

(CVE-2012-2893)\n\n - An error exists related to graphics context handling.<br />

(CVE-2012-2894)\n\n - An integer overflow error exists related to 'WebGL'.<br />

(CVE-2012-2896)\nSuccessful exploitation of any of these issues could lead to an<br />

application crash or even allow arbitrary code execution, subject to the user's privileges.<br />

Solution: Upgrade to Google Chrome 22.0.1229.79 or later.<br />

CVE-2012-2896<br />

Foursquare app on an Apple iOS mobile device<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

<strong>PVS</strong> ID: 6593 FAMILY: Internet Services RISK: INFO NESSUS ID:Not Available<br />

Description: The remote Apple iOS mobile device is running the Foursquare app. Foursquare is a free<br />

app used to share and save places you visit.<br />

Solution: Ensure that such usage is in aligment with Corporate policy<br />

Family Internet Services 1805

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!