27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

<strong>PVS</strong> ID: 1951 FAMILY: Generic<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a Denial of Service (DoS) attack.\n\nThe<br />

remote host is running a version of Speak Freely that is vulnerable to a Denial of Service<br />

attack that may be exploited by an attacker by sending a malformed GIF (using the "show<br />

your face feature") to the vulnerable host.<br />

Solution: The vendor has discontinued this product.<br />

CVE Not available<br />

Winamp MIDI Plugin Track Size Overflow<br />

<strong>PVS</strong> ID: 1952 FAMILY: Generic<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a buffer overflow.\n\nWinamp versions 2.91<br />

and below suffer from a vulnerability which allows an attacker to overflow the client with a<br />

specially crafted MIDI file. Mass exploitation of this vulnerability would be relatively easy<br />

for an attacker with a streaming media server.<br />

Solution: Upgrade or patch according to vendor recommendations.<br />

CVE Not available<br />

Citrix MetaFrame Service Enumeration<br />

<strong>PVS</strong> ID: 1953 FAMILY: Generic<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:11138<br />

Description: Synopsis :\n\nThe remote host may give an attacker information useful for future<br />

attacks.\n\nThe remote Citrix server is configured in such a way as to allow anonymous<br />

remote users to enumerate services.<br />

Solution: Upgrade or patch according to vendor recommendations.<br />

CVE Not available<br />

LDAP NULL Base Connection<br />

<strong>PVS</strong> ID: 1954 FAMILY: Generic<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

RISK:<br />

MEDIUM<br />

NESSUS ID:10722<br />

Description: Synopsis :\n\nThe remote host may give an attacker information useful for future<br />

attacks.\n\nImproperly configured LDAP servers will allow the directory BASE to be set to<br />

NULL. This allows information to be gathered without any prior knowledge of the<br />

directory structure. Coupled with a NULL BIND, an anonymous user can query your<br />

LDAP server using a tool such as LdapMiner.<br />

Family Internet Services 498

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!