27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Solution: Upgrade or patch according to vendor recommendations.<br />

CVE Not available<br />

Apple iTunes < 4.7.1 Playlist Buffer Overflow<br />

<strong>PVS</strong> ID: 2519 FAMILY: Web Clients<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a Denial of Service (DoS) attack.\n\nThe<br />

remote host is using iTunes, a media player application for Windows and Mac OS X. The<br />

remote version of this software is vulnerable to a buffer overflow. This may allow an<br />

attacker to execute code on the remote host. An attacker needs to send a malicious playlist<br />

to the user to exploit this flaw.<br />

Solution: Upgrade to version 4.7.1 or higher.<br />

CVE-2005-0043<br />

Squid Proxy < 2.5.STABLE8 Multiple Vulnerabilities<br />

<strong>PVS</strong> ID: 2520 FAMILY: Web Servers RISK: LOW NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a Denial of Service (DoS) attack.\n\nThe<br />

remote Squid caching proxy, according to its version number, may be vulnerable to a<br />

remote denial of service.\n\nThis flaw is caused due to an input validation error in the<br />

NTLM module.\n\nAn attacker can exploit this flaw to crash the server with a specially<br />

crafted packet.\n\nThe remote Squid proxy is also vulnerable to a cache-corruption flaw<br />

due to incorrect parsing of malformed HTTP headers. An attacker exploiting this flaw<br />

would be able to poison the cache.\n\nThe remote Squid proxy is vulnerable to an<br />

authentication bypass\nin the squid_ldap_auth module as well as a remote overflow due to<br />

oversized HTTP headers.<br />

Solution: Upgrade to Squid 2.5.STABLE8 or higher.<br />

CVE-2005-0211<br />

Gracebyte <strong>Network</strong> Assistant Remote DoS<br />

<strong>PVS</strong> ID: 2521 FAMILY: Web Clients RISK: LOW NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a Denial of Service (DoS) attack.\n\nThe<br />

remote host is using Gracebyte <strong>Network</strong> Assistant, a chat and instant messenger program<br />

for home and small office. The remote version of this software is vulnerable to a denial of<br />

service flaw. This may allow an attacker to crash the remote service.<br />

Solution: No solution is known at this time.<br />

CVE Not available<br />

VideoDB < 2.0.2 Multiple Vulnerabilities<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

Family Internet Services 641

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!