27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

RISK:<br />

MEDIUM<br />

Description: Synopsis :\n\nThe remote host is vulnerable to multiple attack vectors.\n\nThe remote host<br />

seems to be running either Gaim, a popular open-source multi-protocol instant messenger,<br />

either Ultramagnetic, a clone of Gaim that includes encryption features. It is reported that<br />

the version of the running software is prone to 12 security problems including buffer and<br />

stack overflows. These vulnerabilities may permit an attacker to execute arbitrary code on<br />

the remote host.<br />

Solution: Upgrade to Gaim version 0.76 or higher or to Ultramagnetic 0.81.0 or higher.<br />

CVE-2004-0008<br />

Gaim < 0.59.1 Remote Command Execution<br />

<strong>PVS</strong> ID: 2162 FAMILY: Internet Messengers<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a buffer overflow.\n\nThe remote host<br />

seems to be running Gaim, a popular open-source multi-protocol instant messenger. It is<br />

reported that this version of Gaim is prone to a remote command execution issue. An<br />

attacker may send malicious code encoded in hyperlinks in instant messages that will be<br />

executed by the remote host.<br />

Solution: Upgrade to version 0.59.1 or higher.<br />

CVE-2002-0989<br />

Gaim < 0.59 Web Mail Account Information Disclosure<br />

<strong>PVS</strong> ID: 2163 FAMILY: Internet Messengers RISK: LOW NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a flaw that allows attackers to retrieve<br />

sensitive files or data.\n\nThe remote host appears to be running Gaim, a popular<br />

open-source multi-protocol instant messenger. It is reported that this version of Gaim is<br />

prone to an information disclosure issue. If the user configures Gaim to check a web mail<br />

account, the program may create two world readable files in /tmp during the operation that<br />

contain sensitive information about the account.<br />

Solution: Upgrade to version 0.59 or higher.<br />

CVE-2002-0377<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

Keene Digital Media Server Directory Traversal Arbitrary File Access<br />

<strong>PVS</strong> ID: 2164 FAMILY: Web Servers RISK: LOW NESSUS ID:Not Available<br />

Family Internet Services 540

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!