27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

this issue, an unauthenticated remote attacker is able to crash the remote service and<br />

possibly execute arbitrary code remotely.<br />

Solution: Upgrade to version 4.01b or higher.<br />

CVE-2005-4411<br />

Mercury PH Server Detection<br />

<strong>PVS</strong> ID: 3384 FAMILY: Generic RISK: INFO NESSUS ID:Not Available<br />

Description: The remote host is running the Mercury PH Server, version %L<br />

Solution: Ensure that you are running the latest version of Mercury PH Server.<br />

CVE Not available<br />

Shareaza P2P Fileshare Client Integer Overflow<br />

<strong>PVS</strong> ID: 3385 FAMILY: Peer-To-Peer File Sharing RISK: HIGH NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is vulnerable to a remote overflow.\n\nThe remote host is<br />

using Shareaza, a peer-to-peer (P2P) fileshare client. This version of Shareaza is vulnerable<br />

to a flaw in the way that it handles integer values. An attacker exploiting this flaw would<br />

send a malformed query to the Shareaza client. Successful exploitation would result in the<br />

attacker executing arbitrary code on the target system.<br />

Solution: Upgrade to a version of Shareaza greater than 2.2.1.0.<br />

TiVo Detection<br />

CVE-2006-0474<br />

<strong>PVS</strong> ID: 3386 FAMILY: Web Servers RISK: INFO NESSUS ID:20813<br />

Description: Synopsis :\n\nThe remote host is a personal video recorder (PVR).\n\nThe remote host is a<br />

TiVo, a personal video recorder. The version as advertised by port banners is:\n\n%L<br />

Solution: Ensure that the use of such devices is authorized by corporate security policy.<br />

CVE Not available<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

Communigate Pro < 5.0.7 LDAP Module BER Decoding DoS<br />

<strong>PVS</strong> ID: 3387 FAMILY: Web Servers RISK: HIGH NESSUS ID:20827<br />

Description: Synopsis :\n\nThe remote application is prone to denial of service attacks.\n\nThe remote<br />

host appears to be running CommuniGate Pro, a commercial email and groupware<br />

application. The version of CommuniGate Pro installed on the remote host includes an<br />

LDAP server that reportedly fails to handle requests with negative BER lengths. A user can<br />

leverage this issue to crash not just the LDAP server but also the entire application on the<br />

Family Internet Services 870

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!