27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Description: Synopsis :\n\nThe remote web server uses a version of PHP that is affected by a<br />

man-in-the-middle attack.\n\nFor your information, the version of PHP installed on the<br />

remote host is :\n %L \n\nPHP versions 5.4.x earlier than 5.4.11 are affected by a weakness<br />

in the cURL extension that call allow SSL spoofing and man-in-the-middle<br />

attacks.\n\nWhen attempting to validate a certificate, the cURL library (libcurl) fails to<br />

verify that a server hostname matches a domain name in an X.509 certificate's 'Subject<br />

Common Name' (CN) or 'SubjectAltName'.\n\nNote that this plugin does not attempt to<br />

verify whether the PHP install has been built with the cURL extention but instead relies<br />

only on PHP's self-reported version number.<br />

Solution: Upgrade to PHP version 5.4.11 or later.<br />

CVE Not available<br />

Google Chrome < 24.0.1312.56 Multiple Vulnerabilities<br />

<strong>PVS</strong> ID: 6673 FAMILY: Web Clients RISK: HIGH NESSUS ID:63645<br />

Description: Synopsis :\n\nThe remote host contains a web browser that is affected by multiple<br />

vulnerabilities.\n\nFor your information, the observed version of Google Chrome is :\n %L<br />

\n\nVersions of Google Chrome earlier than 24.0.1312.56 are potentially affected by the<br />

following vulnerabilities :\n\n - A use-after-free vulnerability exists related to font handling<br />

and canvas. (CVE-2013-0839)\n\n - An error exists related to URL validation and the<br />

opening of new browser windows. (CVE-2013-0840)\n\n - An array index is not properly<br />

checked in relation to content blocking. (CVE-2013-0841)\n\n - An unspecified error exists<br />

related to handling null characters in embedded paths. (CVE-2013-0842)\n\nSuccessful<br />

exploitation of some of these issues could lead to an application crash or even allow<br />

arbitrary code execution, subject to the user's privileges.<br />

Solution: Upgrade to Google Chrome 24.0.1312.56 or later.<br />

CVE-2013-0842<br />

MySQL Server 5.5.x < 5.5.29 Multiple Vulnerabilities<br />

<strong>PVS</strong> ID: 6674 FAMILY: Database RISK: HIGH NESSUS ID:63618<br />

Description: Synopsis :\n\nThe remote database server is affected by multiple vulnerabilities.\n\nFor<br />

your information, the observed version of MySQL server is \n %L \n\nThe version of<br />

MySQL 5.5 installed on the remote host is earlier than 5.5.29. Therefore, affected by<br />

vulnerabilities in the following components :\n\n - Information Schema\n\n - InnoDB\n\n -<br />

MyISAM\n\n - Server\n\n - Server Locking\n\n - Server Optimizer\n\n - Server Parser\n\n -<br />

Server Partition\n\n - Server Privileges\n\n - Server Replication\n\n - Stored Procedure<br />

Solution: Upgrade to MySQL Server 5.5.29 or later<br />

CVE-2013-0389<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

MySQL Server 5.1.x < 5.1.67 Multiple Vulnerabilities<br />

Family Internet Services 1836

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!