27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Description: Synopsis :\n\nThe remote host is vulnerable to a buffer overflow.\n\nThe remote host is<br />

running MusicMatch, a music player. The remote version of this software is vulnerable to a<br />

buffer overflow condition as well as a cross-site scripting vulnerability. An attacker may<br />

exploit these flaws to execute arbitrary code on the remote host.<br />

Solution: Upgrade to version 10.0.2048, 9.0.5066 or higher.<br />

CVE-2005-1185<br />

Apple Mac OS X < 10.3.9 Multiple Vulnerabilities<br />

<strong>PVS</strong> ID: 2833 FAMILY: Operating System Detection RISK: HIGH NESSUS ID:18062<br />

Description: Synopsis :\n\nThe remote host is missing a critical security patch or upgrade.\n\nThe<br />

remote host is running a version of Mac OS X 10.3 that is older than version 10.3.9.\nMac<br />

OS X 10.3.9 contains several security fixes for :\n- Safari : a remote local zone script<br />

execution vulnerability has been fixed\n - kernel : multiple local privilege escalation<br />

vulnerabilities have been fixed\n<br />

Solution: http://docs.info.apple.com/article.html?artnum<br />

CVE-2005-0971<br />

Kerio MailServer < 6.0.9 Malformed Email DoS<br />

<strong>PVS</strong> ID: 2834 FAMILY: SMTP Servers RISK: HIGH NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a buffer overflow.\n\nThe remote<br />

host is running a version of Kerio MailServer prior to 6.0.9. There is an<br />

undisclosed flaw in the remote version of this server that might allow an attacker<br />

to exhaust resources (impact availability) on the Kerio MailServer.<br />

Solution: Upgrade to Kerio MailServer 6.0.9 or higher.<br />

CVE-2005-1138<br />

Monkey HTTP Daemon < 0.9.1 Multiple Vulnerabilities<br />

<strong>PVS</strong> ID: 2835 FAMILY: Web Servers RISK: HIGH NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is vulnerable to multiple attack vectors.\n\nThe version of<br />

the Monkey HTTP Server installed on the remote host suffers from the following flaws:\n\n<br />

- A format string vulnerability. A remote attacker may be able to execute arbitrary code<br />

with the permissions of the user running monkeyd by sending a specially-crafted<br />

request.\n\n - A denial of service vulnerability. Repeated requests for a zero-byte length<br />

file, if one exists, could cause the web server to crash.<br />

Solution: Upgrade to version 0.9.1 or higher.<br />

CVE-2005-1123<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

Family Internet Services 731

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!