12.07.2015 Views

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

Symantec™ Security Gateways Reference Guide - Sawmill

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

362 IDS eventsSignaturesAffected: Apache Software Foundation Tomcat 4.0.3False Positives: None known.<strong>Reference</strong>sCAN-2002-0682<strong>Security</strong> Focus BID: 5193Info2www CGI Command ExecBase Event:Details:Response:INFO2WWW_CGI_CMD_EXECThe info2www script allows HTTP access to information stored in GNU EMACS Info Nodes. Thisscript fails to properly parse input and is used to execute commands on the server withpermissions of the Web server, by passing commands as part of a variable. Potential consequencesof a successful exploitation involve anything the Web server process has permissions to do,including possibly Web site defacement.Version 1.2 of the script does not suffer from this issue. Upgrade to the latest version.Affected: Roar Smith info2www 1.0 to 1.1.False Positives: None known.<strong>Reference</strong>sCVE-1999-0266<strong>Security</strong> Focus BID: 1995MSSQL NULL Packet DOSBase Event:Details:Response:MSSQL_NULL_PACKET_DOSIf Microsoft SQL Server 7.0 receives a TDS header with three or more NULL bytes as data it willcrash. The crash will generate an event in the log with ID 17055 “fatal exceptionEXCEPTION_ACCESS VIOLATION”.Contact Microsoft for the latest updates.Affected: Microsoft SQL Server 7.0False Positives: None known.<strong>Reference</strong>sMicrosoft <strong>Security</strong> Bulletin: MS-059

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!