27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

CVE Not available<br />

OpenSSH < 4.1.0p2 / 4.2 Timing Attack<br />

<strong>PVS</strong> ID: 3787 FAMILY: SSH RISK: LOW NESSUS ID:Not Available<br />

Description: Synopsis : \n\nThe remote host discloses information regarding the availability of user<br />

accounts.\n\nThe remote host is running a version of OpenSSH that is vulnerable to a flaw<br />

in the way that it handles authentication requests. Specifically, OpenSSH is alleged to vary<br />

response time based on the complexity (or availability) of the user password. An account<br />

that had no password would elicit a quicker SSH response than an account that had a<br />

defined password. An attacker exploiting this flaw would be able to determine local<br />

accounts that had passwords. This information would be useful in other more complex<br />

attacks. Tthe reported version of SSH is: \n %L<br />

Solution: Upgrade to version 4.2, 4.1.0p2 or higher.<br />

CVE-2006-5229<br />

ZABBIX Multiple Overflows<br />

<strong>PVS</strong> ID: 3788 FAMILY: CGI RISK: HIGH NESSUS ID:Not Available<br />

Description: Synopsis :\n\nThe remote host is vulnerable to multiple attack vectors.\n\nThe remote<br />

server is running ZABBIX, an open-source tool that is used to manage network devices.<br />

This version of ZABBIX is vulnerable to a flaw in the way that it handles agent data. An<br />

attacker spoofing an agent would be able to exploit a number of flaws that would give the<br />

attacker the rights of the ZABBIX server.<br />

Solution: No solution is known at this time.<br />

CVE-2006-6693<br />

ZABBIX Client Detection<br />

<strong>PVS</strong> ID: 3789 FAMILY: Generic RISK: INFO NESSUS ID:Not Available<br />

Description: The remote host is running the ZABBIX client. ZABBIX is a client-server application that<br />

allows a central server to collect and manage results from multiple clients.<br />

Solution: N/A<br />

CVE Not available<br />

LogMeIn Listening Server Detection<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

<strong>PVS</strong> ID: 3790 FAMILY: Policy RISK: LOW NESSUS ID:Not Available<br />

Family Internet Services 979

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!