27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Solution: Upgrade to the latest version of Elm (available at www.instinct.org/elm)<br />

Pegasus Mail <<br />

CVE Not available<br />

<strong>PVS</strong> ID: 1301 FAMILY: SMTP Clients RISK: HIGH NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a buffer overflow.\n\nThe remote host is<br />

running Pegasus 3.11 mail client which contains a vulnerability, where if more than<br />

approximately 90KB of binary data is placed in the body of a message, an overflow will<br />

occur, causing the program to crash and/or allowing for the execution of arbitrary code.<br />

Solution: Upgrade to the latest version of Pegasus.<br />

Pegasus Mail <<br />

CVE-2000-0931<br />

<strong>PVS</strong> ID: 1302 FAMILY: SMTP Clients<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host may be tricked into uploading confidential files to a<br />

malicious webserver.\n\nThe remote host is running the Pegasus 3.12c mail client. This<br />

version contains a vulnerability whereby a malicious website operator may be able to<br />

obtain copies of known files on a remote system if a website visitor is running the 3.12c<br />

version of the Pegasus client.<br />

Solution: Upgrade to the latest version of Pegasus.<br />

CVE-2000-0930<br />

Pegasus Mail < 4.02 To/From Header Overflow DoS<br />

<strong>PVS</strong> ID: 1303 FAMILY: SMTP Clients<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a Denial of Service (DoS) attack.\n\nThe<br />

remote host is running the Pegasus 4.01 mail client. Pegasus Mail 4.01 (and possibly earlier<br />

versions) are vulnerable to a Denial of Service attack caused by a buffer overflow. By<br />

sending an email message containing 259 characters or more in either the "From" or "To"<br />

message header, a remote attacker can overflow a buffer and crash the system.<br />

Solution: Upgrade to Pegasus Mail 4.02 or higher.<br />

CVE-2002-1075<br />

Lotus Notes R5 S/MIME Message Modification Warning Failure<br />

<strong>PVS</strong> ID: 1304 FAMILY: SMTP Clients<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

RISK:<br />

MEDIUM<br />

NESSUS ID:Not Available<br />

Family Internet Services 333

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!