27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Description: Synopsis :\n\nThe remote host is vulnerable to a Denial of Service (DoS) attack\n\nThe<br />

remote host is running Microsoft MSN Messenger. Certain versions of MSN messenger are<br />

vulnerable to a Denial of Service attack. Specifically, a message received with a malformed<br />

invite request containing HTML-encoded space characters (%20) in the Invitation-Cookie<br />

field may cause an MSN client to crash. A remote attacker may use this vulnerability to<br />

create a Denial of Service attack.<br />

Solution: Upgrade to the latest version of MSN Messenger.<br />

CVE-2002-1831<br />

MSN Messenger Malformed Font Field Remote DoS<br />

<strong>PVS</strong> ID: 1268 FAMILY: Internet Messengers<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a Denial of Service (DoS) attack\n\nThe<br />

remote host is running Microsoft MSN Messenger. Certain versions of MSN messenger are<br />

vulnerable to a Denial of Service attack. Specifically, a message received with a large<br />

amount of data (HTML encoded spaces %20 in particular) in the font field of the message<br />

header can cause the MSN client to crash. This vulnerability can be exploited by a remote<br />

attacker to continuously crash a victim's IM client, causing a Denial of Service.<br />

Solution: Upgrade to the latest version of MSN Messenger<br />

CVE-2002-1698<br />

MSN Messenger Detection<br />

<strong>PVS</strong> ID: 1269 FAMILY: Internet Messengers RISK: LOW NESSUS ID:Not Available<br />

Description: The remote host is running Microsoft MSN Messenger version %L.<br />

Solution: Ensure this software meets corporate guidelines for employee use.<br />

CVE Not available<br />

AOL Instant Messenger Detection<br />

<strong>PVS</strong> ID: 1270 FAMILY: Internet Messengers RISK: LOW NESSUS ID:Not Available<br />

Description: The remote host is running AOL Instant Messenger version %L.<br />

Solution: Ensure this software meets corporate guidelines for employee use.<br />

CVE Not available<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

Yahoo! Messenger Download Feature Long Filename Overflow<br />

<strong>PVS</strong> ID: 1271 FAMILY: Internet Messengers RISK: HIGH NESSUS ID:Not Available<br />

Family Internet Services 324

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!