27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Description: Synopsis :\n\nThe remote host is vulnerable to a buffer overflow.\n\nThe remote host<br />

appears to be running Gaim, a popular open-source multi-protocol instant messenger. It is<br />

reported that this version of Gaim is prone to multiple vulnerabilities that may allow an<br />

attacker to disable this client remotely or to execute arbitrary code on the remote host.<br />

Solution: Update to Gaim 1.0.2 or higher.<br />

CVE Not available<br />

Serendipity < 0.7.0rc1 HTTP Response Splitting<br />

<strong>PVS</strong> ID: 2367 FAMILY: Web Servers<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:15543<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a Cross-Site Scripting (XSS) attack.\n\nThe<br />

remote host is running Serendipity, a weblog written in PHP.\nThe remote version of this<br />

software is vulnerable to a HTTP response splitting vulnerability that may allow an attacker<br />

to perform a cross-site scripting attack against the remote host.<br />

Solution: Upgrade to Serendipity 0.7.0rc1 or higher.<br />

CVE-2004-1620<br />

MacOS X Application Crash Plaintext Report<br />

<strong>PVS</strong> ID: 2368 FAMILY: Generic<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:Not Available<br />

Description: The remote MacOS X Client is reporting a MacOS application error via the network.<br />

Solution: Ensure that passing such reports via the Internet is in accordance with existing corporate<br />

policies. The reports usually include crash dumps that may contain sensitive information<br />

about the remote host environment.<br />

CVE Not available<br />

MySQL < 4.0.21 Remote FULLTEXT Search DoS<br />

<strong>PVS</strong> ID: 2369 FAMILY: Database<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:15477<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a Denial of Service (DoS) attack.\n\nThe<br />

remote host is running a version of MySQL that is older than version 4.0.21.\nIt is<br />

vulnerable to a flaw that may allow an attacker to cause a Denial Of Service. An attacker<br />

can exploit this vulnerability by using the FULLTEXT search functionality.<br />

Solution: Upgrade to version 4.0.21 or higher.<br />

CVE-2004-0956<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

Family Internet Services 598

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!