27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

<strong>PVS</strong> ID: 1320 FAMILY: SMTP Clients RISK: HIGH NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a buffer overflow.\n\nThe remote host is<br />

running a version of the Mozilla browser that may contain a buffer overflow vulnerability.<br />

An integer overflow vulnerability has been reported for the Netscape/Mozilla POP3 mail<br />

handler routines. Reportedly, insufficient checks are performed on some server supplied<br />

values. An attacker may exploit this vulnerability through an attacker-controlled POP3<br />

server. By issuing a very large integer value that is used by the Netscape/Mozilla POP3<br />

mail handler, it may be possible to cause an integer overflow condition and allocate a<br />

buffer that is too small. Successful exploitation of this vulnerability may allow an attacker<br />

to obtain control over the execution of the vulnerable Mozilla process.<br />

Solution: Upgrade to the latest version of Mozilla.<br />

CVE Not available<br />

Mozilla Browser Large HTTP Header Handling Overflow<br />

<strong>PVS</strong> ID: 1321 FAMILY: SMTP Clients RISK: HIGH NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a buffer overflow.\n\nThe remote host is<br />

running a version of the Mozilla browser that may contain a buffer overflow vulnerability.<br />

The condition occurs when HTTP responses of excessive length are received from remote<br />

servers.<br />

Solution: Upgrade to Mozilla 1.0.1, 1.1 or higher.<br />

CVE Not available<br />

Mozilla JAR File Decompression Heap Overflow<br />

<strong>PVS</strong> ID: 1322 FAMILY: SMTP Clients RISK: HIGH NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a heap overflow.\n\nThe remote host is<br />

running a version of the Mozilla browser that may contain a heap corruption vulnerability.<br />

A vulnerability has been discovered in the JAR URI handler used by Netscape and Mozilla.<br />

By constructing a malformed JAR file containing invalid file length information, it is<br />

possible to cause heap corruption in a vulnerable browser. When a client attempts to<br />

decompress a malicious JAR file, invalid values will be used to allocate buffer space for the<br />

inflated data. As there are no checks to prevent this, an overrun condition in the heap may<br />

occur if excessive data is decompressed.<br />

Solution: Upgrade to the latest version of Mozilla.<br />

CVE-2002-1308<br />

Mozilla Browser 'onclick' Property Cross Domain Violation<br />

<strong>PVS</strong> ID: 1323 FAMILY: SMTP Clients<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

RISK:<br />

MEDIUM<br />

NESSUS ID:Not Available<br />

Family Internet Services 339

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!