27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

loss of integrity and confidentiality.<br />

Solution: Upgrade to version 2.0.4, 2.1.0 Alpha 3 or higher.<br />

CVE-2005-1443<br />

Leafnode < 1.11.2 Abrupt Disconnect DoS<br />

<strong>PVS</strong> ID: 2880 FAMILY: Generic<br />

RISK:<br />

MEDIUM<br />

NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a Denial of Service (DoS) attack.\n\nThe<br />

remote host is running the LeafNode NNTP server. The version of LeafNode is vulnerable<br />

to a remote Denial of Service (DoS) attack. Specifically, when an upstream NNTP server<br />

requests a header and then abruptly terminates the connection, the LeafNode NNTP server<br />

fails. Successful exploitation would result in a loss of availability.<br />

Solution: Upgrade to version 1.11.2 or higher.<br />

CVE-2005-1453<br />

Oracle Application Server < 10.1.0.0.3 Privilege Escalation<br />

<strong>PVS</strong> ID: 2881 FAMILY: Web Servers RISK: HIGH NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a flaw that allows for the<br />

bypassing of authentication.\n\nThe remote host is running the Oracle<br />

Application Server. This version is reported vulnerable to a privilege escalation<br />

flaw. Specifically, users with the 'create job' privileges can obtain<br />

administrative access to the database. An attacker exploiting this flaw would<br />

need a valid account that had the ability to create new database jobs. Successful<br />

exploitation would result in the attacker being able to read or write confidential<br />

data.<br />

Solution: Upgrade to version 10.1.0.0.3 or higher.<br />

CVE-2005-1496<br />

Oracle Application Server < 10.1.0.0.4 Logging Service Interruption<br />

<strong>PVS</strong> ID: 2882 FAMILY: Web Servers<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

RISK:<br />

MEDIUM<br />

NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a flaw that would allow a single user to<br />

affect logging-level changes for all users of a database.\n\nThe remote host is running the<br />

Oracle Application Server. This version is reported vulnerable to a flaw where a SYS user<br />

can disable Fine Grained Auditing (FGA) which then impacts the logging level of all users<br />

of the database.<br />

Solution: Upgrade to version 10.1.0.0.4 or higher.<br />

Family Internet Services 745

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!