27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Solution: Upgrade to the latest version of AOL Instant Messenger.<br />

CVE Not available<br />

AOL Instant Messenger Login Sequence Remote Overflow<br />

<strong>PVS</strong> ID: 1257 FAMILY: Internet Messengers RISK: HIGH NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a buffer overflow\n\nThe remote host is<br />

running AOL Instant Messenger (AIM). Certain versions of AIM contain a buffer overflow<br />

in the packet processing routines for the login process. Exploitation of this vulnerability<br />

may allow for execution of arbitrary code on the victim's machine.<br />

Solution: Upgrade to the latest version of AOL Instant Messenger.<br />

CVE Not available<br />

AOL Instant Messenger ASCII-Symbol Interpretation Denial of Service<br />

<strong>PVS</strong> ID: 1258 FAMILY: Internet Messengers RISK: HIGH NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a buffer overflow\n\nThe remote host is<br />

running AOL Instant Messenger (AIM). Certain versions of AIM contain a buffer overflow<br />

in the packet processing routines for the login process. Exploitation of this vulnerability<br />

may allow for execution of arbitrary code on the victims machine.<br />

Solution: Upgrade to the latest version of AOL Instant Messenger<br />

CVE Not available<br />

AOL Instant Messenger Password Encryption Weakness<br />

<strong>PVS</strong> ID: 1259 FAMILY: Internet Messengers RISK: LOW NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host passes information across the network in an insecure<br />

manner\n\nThe remote host is running AOL Instant Messenger (AIM). Version 1.2 of AIM<br />

uses a very weak encryption scheme to protect user passwords. A remote attacker may<br />

determine a user's password given only the encrypted form of the password (by sniffing the<br />

login process for example).<br />

Solution: Upgrade to the latest version of AOL Instant Messenger.<br />

CVE Not available<br />

Yahoo! Messenger Shared File Access User Status Enumeration<br />

<strong>PVS</strong> ID: 1260 FAMILY: Internet Messengers<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

RISK:<br />

MEDIUM<br />

NESSUS ID:Not Available<br />

Family Internet Services 321

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!