27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Description: Synopsis :\n\nThe remote host is vulnerable to a buffer overflow\n\nThe remote host is<br />

running a version of Yahoo Instant Messenger that is vulnerable to a buffer overflow in the<br />

code that processes user-initiated file transfer requests. A successful attacker would be able<br />

to execute malicious code under the same privileges that Yahoo! Messenger is running<br />

under.<br />

Solution: Upgrade to the latest version of Yahoo Instant Messenger.<br />

CVE-2004-0043<br />

Yahoo! Messenger Peer To Peer File Sharing Detection<br />

<strong>PVS</strong> ID: 1272 FAMILY: Internet Messengers<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:11993<br />

Description: The remote host is running the Yahoo! Messenger Peer To Peer application.<br />

Solution: Ensure that this activity matches corporate standards and security guidelines.<br />

CVE Not available<br />

Yahoo! Messenger Detection<br />

<strong>PVS</strong> ID: 1273 FAMILY: Internet Messengers RISK: LOW NESSUS ID:Not Available<br />

Description: The remote host is running a Yahoo Instant Messenger client.<br />

Solution: Ensure this software meets corporate guidelines for employee use.<br />

CVE Not available<br />

AOL Instant Messenger aim:goaway URI Handler goaway Function Away Message Handling Remote<br />

Overflow<br />

<strong>PVS</strong> ID: 1274 FAMILY: Internet Messengers RISK: HIGH NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a buffer overflow\n\nThe remote host is<br />

running AOL Instant Messenger (AIM). In versions 5.5.3595 and 5.5, a remote attacker can<br />

execute arbitrary code to gain unauthorized access on the client's machine by sending a<br />

specially crafted overly long 'Away' message through a link or a malicious website.<br />

Solution: Upgrade to AOL Instant Messenger 5.9 or later.<br />

CVE-2004-0636<br />

Yahoo! Messenger Detection<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

<strong>PVS</strong> ID: 1275 FAMILY: Internet Messengers RISK: INFO NESSUS ID:Not Available<br />

Family Internet Services 325

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!