27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Solution: http://www.microsoft.com/technet/security/bulletin/MS04-036.mspx<br />

CVE-2004-0840<br />

Microsoft NNTP Component Remote Overflow (883935)<br />

<strong>PVS</strong> ID: 2360 FAMILY: Generic RISK: HIGH NESSUS ID:15465<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a buffer overflow.\n\nThe remote host is<br />

running a version of Microsoft NNTP server that is vulnerable to a buffer overflow<br />

issue.\n\nAn attacker may exploit this flaw to execute arbitrary commands on the remote<br />

host with the privileges of the NNTP server process.<br />

Solution: http://www.microsoft.com/technet/security/bulletin/MS04-036.mspx<br />

CVE-2004-0840<br />

MySQL < 3.23.59 Multiple Vulnerabilities (2)<br />

<strong>PVS</strong> ID: 2361 FAMILY: Database RISK: HIGH NESSUS ID:15449<br />

Description: Synopsis :\n\nThe remote host is vulnerable to multiple attack vectors.\n\nThe remote host<br />

is running a version of the MySQL database that is older than 3.23.59.\n\nMySQL is a<br />

database that runs on both Linux/BSD and Windows platforms.\nThe remote version of this<br />

software is vulnerable to specially crafted ALTER TABLE SQL query that can be<br />

exploited to bypass some applied security restrictions or cause a denial of service.\n\nTo<br />

exploit this flaw, an attacker would need the ability to execute arbitrary SQL statements on<br />

the remote host.<br />

Solution: Upgrade to version 3.23.59 or higher.<br />

CVE-2004-0835<br />

MySQL < 4.0.21 Multiple Vulnerabilities (2)<br />

<strong>PVS</strong> ID: 2362 FAMILY: Database RISK: HIGH NESSUS ID:15449<br />

Description: Synopsis :\n\nThe remote host is vulnerable to multiple attack vectors.\n\nThe remote host<br />

is running a version of the MySQL database that is older than 4.0.21.\n\nMySQL is a<br />

database that runs on both Linux/BSD and Windows platforms.\nThe remote version of this<br />

software is vulnerable to specially crafted ALTER TABLE SQL query that can be<br />

exploited to bypass some applied security restrictions or cause a denial of service.\n\nTo<br />

exploit this flaw, an attacker would need the ability to execute arbitrary SQL statements on<br />

the remote host.<br />

Solution: Upgrade to version 4.0.21 or higher.<br />

CVE-2004-0835<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

Squid < 2.5.STABLE7 SNMP ASN.1 Parser Remote DoS<br />

Family Internet Services 596

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!