27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Description: Synopsis :\n\nThe remote host is vulnerable to a buffer overflow.\n\nThe remote host is<br />

running a vulnerable version of Icecast, an open-source streaming server. An attacker<br />

exploiting this flaw would only need to be able to connect to the Icecast HTTP port and<br />

send multiple (32) headers. A successful attack would give the attacker the ability to<br />

execute arbitrary code.<br />

Solution: Upgrade to Icecast 2.0.2 or higher.<br />

CVE-2004-1561<br />

Serendipity < 0.7-beta3 Multiple Vulnerabilities<br />

<strong>PVS</strong> ID: 2336 FAMILY: CGI RISK: HIGH NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote web server contains a script that is vulnerable to a SQL injection<br />

attack.\n\nThe remote host is running a vulnerable version of Serendipity Web Log.<br />

Version 0.7beta1 is prone to both cross-site scripting (XSS) and SQL Injection attacks.<br />

Versions prior to 0.7beta3 should also be upgraded.<br />

Solution: Upgrade to version 0.7beta3 or higher.<br />

CVE-2004-2157<br />

Samba < 2.2.11 Remote Arbitrary File Access<br />

<strong>PVS</strong> ID: 2337 FAMILY: Samba<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:15394<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a flaw that allows attackers to retrieve<br />

sensitive files or data.\n\nThe remote Samba server, according to its version number ('%L'),<br />

may be vulnerable to a remote file access vulnerability.\n This vulnerability may allow an<br />

attacker to access arbitrary files that exist outside of the share's defined path.\nAn attacker<br />

needs a valid account to exploit this vulnerability.<br />

Solution: Upgrade to Samba 2.2.11 or higher.<br />

CVE-2004-0815<br />

Samba < 3.0.6 Remote Arbitrary File Access<br />

<strong>PVS</strong> ID: 2338 FAMILY: Samba<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:15394<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a flaw that allows attackers to retrieve<br />

sensitive files or data.\n\nThe remote Samba server, according to its version number, may<br />

be vulnerable to a remote file access vulnerability.\n This vulnerability may allow an<br />

attacker to access arbitrary files that exist outside of the share's defined path.\nAn attacker<br />

needs a valid account to exploit this vulnerability.<br />

Solution: Upgrade to Samba 3.0.6 or higher.<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

Family Internet Services 589

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!