27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Description: Synopsis :\n\nThe remote host is vulnerable to a Cross-Site Scripting (XSS) attack.\n\nThe<br />

remote host is running a vulnerable version of Icecast, an open-source streaming server. It<br />

is reported that every version of the 1.3 branch is vulnerable to a cross scripting issue. An<br />

attacker may steal cookie-based authentication credentials from a legitimate user by<br />

sending malformed links to the Icecast server.<br />

Solution: Upgrade or patch according to vendor recommendations.<br />

CVE-2004-0781<br />

Icecast < 2.0.1 HTTP Basic Authentication Remote Overflow<br />

<strong>PVS</strong> ID: 2137 FAMILY: Web Servers RISK: HIGH NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a buffer overflow.\n\nThe remote host is<br />

running a vulnerable version of Icecast, an open-source streaming server. It is reported that<br />

every version prior to 2.0.1 is vulnerable to a remote buffer overflow during the Base64<br />

authorization request processing. This vulnerability may permit an attacker to execute<br />

arbitrary code on the remote host.<br />

Solution: Upgrade to Icecast 2.0.1 or higher.<br />

CVE-2004-2027<br />

Icecast Server < 2.0.0 list_directory Function Traversal Directory Enumeration<br />

<strong>PVS</strong> ID: 2138 FAMILY: Web Servers<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a directory traversal flaw.\n\nThe remote<br />

host is running a vulnerable version of Icecast, an open-source streaming server. It is<br />

reported that every version prior 2.0.0 is vulnerable to directory traversal issue. This issue<br />

discloses the existence of directory on the remote system that may permit an attacker to<br />

gather information about the host.<br />

Solution: Upgrade to Icecast 2.0.0 or higher.<br />

CVE-2002-1982<br />

Icecast < 1.3.12 Multiple Remote Buffer Overflows<br />

<strong>PVS</strong> ID: 2139 FAMILY: Web Servers RISK: HIGH NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a buffer overflow.\n\nThe remote host is<br />

running a vulnerable version of Icecast, an open-source streaming server. It is reported that<br />

every version up to 1.3.10 is vulnerable to a remote buffer overflow which may permit an<br />

attacker to execute arbitrary code on the host.<br />

Solution: Upgrade to Icecast 1.3.12 or higher.<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

Family Internet Services 533

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!