27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Solution: Upgrade or patch according to vendor recommendations.<br />

rsync Detection<br />

CVE-2002-0690<br />

<strong>PVS</strong> ID: 1896 FAMILY: Generic RISK: LOW NESSUS ID:11389<br />

Description: The remote host is running rsync on this port.<br />

Solution: N/A<br />

CVE Not available<br />

rsync < 2.5.2 Signedness Error Array Overflow<br />

<strong>PVS</strong> ID: 1897 FAMILY: Generic RISK: HIGH NESSUS ID:11390<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a buffer overflow.\n\nThe remote rsync<br />

server might be vulnerable to an array index overflow. An attacker may use this flaw to<br />

gain a shell on this host.<br />

Solution: Upgrade to rsync 2.5.2 or higher.<br />

CVS Server Detection<br />

CVE-2002-0048<br />

<strong>PVS</strong> ID: 1898 FAMILY: Generic RISK: LOW NESSUS ID:Not Available<br />

Description: The remote server is running the CVS daemon. The server is being used as a central file<br />

repository for maintenance of file or package version.<br />

Solution: Ensure that the server is operating under the guidelines as set forth by corporate and<br />

security policies. Examine the possibility of securing the CVS session by using CVS over<br />

SSH.<br />

CVE Not available<br />

CVS < 1.11.5 pserver Directory Request Double Free() Privilege Escalation<br />

<strong>PVS</strong> ID: 1899 FAMILY: Generic RISK: HIGH NESSUS ID:11385<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a buffer overflow.\n\nThe remote CVS<br />

server is vulnerable to a double free() vulnerability that may allow an attacker to gain a<br />

shell on this host.<br />

Solution: Upgrade to CVS 1.11.5 or higher.<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

Family Internet Services 483

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!