<?xml version="1.0" encoding="UTF-8"?>
<rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:admin="http://webns.net/mvcb/" xmlns="http://purl.org/rss/1.0/">

<channel rdf:about="http://www.nessus.org/">
<title>Nessus.org Plugins</title>
<link>http://www.nessus.org/scripts.php</link>
<description>All the newest security checks for the Nessus scanner</description>

<items>
<rdf:Seq>
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=44406" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=44405" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=44404" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=44403" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=44402" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=44401" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=44400" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=44399" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=44398" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=44397" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=44396" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=44395" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=44394" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=44393" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=44392" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=44391" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=44390" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=44389" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=44388" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=44387" />
</rdf:Seq>
</items>
</channel>

<image rdf:about="http://www.nessus.org/images/RssLogo.jpg">
<title>Nessus Plugins</title>
<url>http://www.nessus.org/images/RssLogo.jpg</url>
<link>http://www.nessus.org/</link>
</image>

<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=44406">
<title>Samba Symlink Traversal Arbitrary File Access</title>
<description><![CDATA[Synopsis :<br />
<br />
The remote file server is prone to a symlink attack.<br />
<br />
Description :<br />
<br />
The remote Samba server is configured insecurely and allows a remote<br />
attacker to gain read or possibly write access to arbitrary files on<br />
the affected host.  Specifically, if an attacker has a valid Samba<br />
account for a share that is writable or there is a writable share that<br />
is configured to be a guest account share, he can create a symlink<br />
using directory traversal sequences and gain access to files and<br />
directories outside that share. <br />
<br />
Note that successful exploitation requires that the Samba server's<br />
'wide links' parameter be set to 'yes', which is the default.<br />
<br />
See also :<br />
<br />
<a href="http://archives.neohapsis.com/archives/fulldisclosure/2010-02/0100.html" target="_blank">http://archives.neohapsis.com/archives/fulldisclosure/2010-02/0100.html</a><br />
<a href="http://www.youtube.com/watch?v=NN50RtZ2N74" target="_blank">http://www.youtube.com/watch?v=NN50RtZ2N74</a><br />
<a href="http://www.samba.org/samba/news/symlink_attack.html" target="_blank">http://www.samba.org/samba/news/symlink_attack.html</a><br />
<br />
Solution :<br />
<br />
Set 'wide links = no' in the [global] section of smbd.conf.<br />
<br />
Risk factor :<br />
<br />
High / CVSS Base Score : 7.5<br />
(CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P)<br />
]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=44406</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=44405">
<title>HP-UX Security patch : PHSS_40230</title>
<description><![CDATA[Synopsis :<br />
<br />
The remote host is missing HP-UX PHSS_40230 security update<br />
<br />
Description :<br />
<br />
11.31 ECMT B.05.00 patch<br />
<br />
Solution :<br />
<br />
<a href="ftp://ftp.itrc.hp.com//superseded_patches/hp-ux_patches/11.X/PHSS_40230" target="_blank">ftp://ftp.itrc.hp.com//superseded_patches/hp-ux_patches/11.X/PHSS_40230</a><br />
<br />
Risk factor :<br />
<br />
High<br />
]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=44405</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=44404">
<title>HP-UX Security patch : PHSS_40229</title>
<description><![CDATA[Synopsis :<br />
<br />
The remote host is missing HP-UX PHSS_40229 security update<br />
<br />
Description :<br />
<br />
ECMT B.05.00 patch<br />
<br />
Solution :<br />
<br />
<a href="ftp://ftp.itrc.hp.com//superseded_patches/hp-ux_patches/s700_800/11.X/PHSS_40229" target="_blank">ftp://ftp.itrc.hp.com//superseded_patches/hp-ux_patches/s700_800/11.X/PHSS_40229</a><br />
<br />
Risk factor :<br />
<br />
High<br />
]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=44404</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=44403">
<title>SuSE 11.2 Security Update:  libsnmp15 (2010-02-04)</title>
<description><![CDATA[Synopsis :<br />
<br />
The remote SuSE system is missing a security patch for libsnmp15<br />
<br />
Description :<br />
<br />
This update of net-snmp fixes the following bugs:<br />
- truncated walk of hrSWRunPath (bnc#565586)<br />
- crash when 64-bit counters wrap (bnc#523553)<br />
- unknown host names in snmp traps (bnc#514333)<br />
- sensitive host information disclosure (bnc#475532,<br />
  CVE-2008-6123)<br />
<br />
See also :<br />
<br />
<a href="https://bugzilla.novell.com/show_bug.cgi?id=466805" target="_blank">https://bugzilla.novell.com/show_bug.cgi?id=466805</a><br />
<a href="https://bugzilla.novell.com/show_bug.cgi?id=473328" target="_blank">https://bugzilla.novell.com/show_bug.cgi?id=473328</a><br />
<a href="https://bugzilla.novell.com/show_bug.cgi?id=475532" target="_blank">https://bugzilla.novell.com/show_bug.cgi?id=475532</a><br />
<a href="https://bugzilla.novell.com/show_bug.cgi?id=514333" target="_blank">https://bugzilla.novell.com/show_bug.cgi?id=514333</a><br />
<a href="https://bugzilla.novell.com/show_bug.cgi?id=523553" target="_blank">https://bugzilla.novell.com/show_bug.cgi?id=523553</a><br />
<a href="https://bugzilla.novell.com/show_bug.cgi?id=565586" target="_blank">https://bugzilla.novell.com/show_bug.cgi?id=565586</a><br />
<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-6123" target="_blank">http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-6123</a><br />
<br />
Solution :<br />
<br />
Run yast to install the security patch for libsnmp15<br />
<br />
Risk factor :<br />
<br />
Medium / CVSS Base Score : 5.0<br />
(CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N)<br />
]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=44403</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=44402">
<title>MDVSA-2010:033: squid</title>
<description><![CDATA[Synopsis :<br />
<br />
The remote host is missing the patch for the advisory MDVSA-2010:033 (squid).<br />
<br />
Description :<br />
<br />
A vulnerability have been discovered and corrected in Squid 2.x,<br />
3.0 through 3.0.STABLE22, and 3.1 through 3.1.0.15, which allows<br />
remote attackers to cause a denial of service (assertion failure)<br />
via a crafted DNS packet that only contains a header (CVE-2010-0308).<br />
This update provides a fix to this vulnerability.<br />
<br />
See also :<br />
<br />
<a href="http://wwwnew.mandriva.com/security/advisories?name=MDVSA-2010:033" target="_blank">http://wwwnew.mandriva.com/security/advisories?name=MDVSA-2010:033</a><br />
<br />
Solution :<br />
<br />
Apply the newest security patches from Mandriva.<br />
<br />
Risk factor :<br />
<br />
Medium / CVSS Base Score : 4.0<br />
(CVSS2#AV:N/AC:L/Au:S/C:N/I:N/A:P)<br />
]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=44402</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=44401">
<title>SMB Service Config Enumeration</title>
<description><![CDATA[Synopsis :<br />
<br />
It is possible to enumerate configuration parameters of remote<br />
services.<br />
<br />
Description :<br />
<br />
This plugin implements the QueryServiceConfig() calls to obtain,<br />
using the SMB protocol, the launch parameters of each active service<br />
on the remote host (executable path, log on type, etc).<br />
<br />
Solution :<br />
<br />
Ensure that each service is configured properly.<br />
<br />
Risk factor :<br />
<br />
None<br />
]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=44401</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=44400">
<title>Squid &lt; 3.0.STABLE19 / 3.1.0.14 / 2.6.STABLE23 strListGetItem Function Remote DoS</title>
<description><![CDATA[Synopsis :<br />
<br />
The remote proxy server is prone to a denial of service attack.<br />
<br />
Description :<br />
<br />
According to its banner, the version of the Squid proxy caching<br />
server installed on the remote host is older than 3.0.STABLE19 /<br />
3.1.0.14 / 2.6.STABLE23.  A bug in the 'strListGetItem()' function in<br />
'src/HttpHeaderTools.c' can result in an infinite loop when processing<br />
a specially crafted auth header with certain comma delimiters. <br />
<br />
A remote attacker may be able to leverage this issue to cause a denial<br />
of service.<br />
<br />
See also :<br />
<br />
<a href="http://bugs.squid-cache.org/show_bug.cgi?id=2541" target="_blank">http://bugs.squid-cache.org/show_bug.cgi?id=2541</a><br />
<a href="http://www.nessus.org/u?d0f03356" target="_blank">http://www.nessus.org/u?d0f03356</a> (3.0.STABLE19 release notes)<br />
<a href="http://www.nessus.org/u?8bf8993a" target="_blank">http://www.nessus.org/u?8bf8993a</a> (3.1.0.14 release notes)<br />
<a href="http://www.nessus.org/u?d23f7691" target="_blank">http://www.nessus.org/u?d23f7691</a> (2.6.STABLE23)<br />
<br />
Solution :<br />
<br />
Upgrade to Squid version 3.0.STABLE19 / 3.1.0.14 / 2.6.STABLE23 or<br />
later.<br />
<br />
Risk factor :<br />
<br />
Medium / CVSS Base Score : 5.0<br />
(CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P)<br />
]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=44400</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=44399">
<title>USN894-1 : linux, linux-source-2.6.15 vulnerabilities</title>
<description><![CDATA[Synopsis :<br />
<br />
These remote packages are missing security patches :<br />
- linux-doc <br />
- linux-doc-2.6.15 <br />
- linux-doc-2.6.24 <br />
- linux-doc-2.6.27 <br />
- linux-doc-2.6.28 <br />
- linux-ec2-doc <br />
- linux-ec2-source-2.6.31 <br />
- linux-headers-2.6.15-55 <br />
- linux-headers-2.6.15-55-386 <br />
- linux-headers-2.6.15-55-686 <br />
- linux-headers-2.6.15-55-amd64-generic <br />
- linux-headers-2.6.15-55-amd64-k8 <br />
- linux-headers-2.6.15-55-amd64-server <br />
- linux-headers-2.6.15-55-amd64-xeon <br />
- linux-headers-2.6.15-55-k7 <br />
- linux-headers-2.6.15-55-powerpc <br />
- linux-head<br />
[...]<br />
<br />
Description :<br />
<br />
Amerigo Wang and Eric Sesterhenn discovered that the HFS and ext4<br />
filesystems did not correctly check certain disk structures. If a user<br />
were tricked into mounting a specially crafted filesystem, a remote<br />
attacker could crash the system or gain root privileges. (CVE-2009-4020,<br />
CVE-2009-4308)<br />
<br />
It was discovered that FUSE did not correctly check certain requests.<br />
A local attacker with access to FUSE mounts could exploit this to<br />
crash the system or possibly gain root privileges.  Ubuntu 9.10 was not<br />
affected. (CVE-2009-4021)<br />
<br />
It was discovered that KVM did not correctly decode certain guest<br />
instructions.  A local attacker in a guest could exploit this to<br />
trigger high scheduling latency in the host, leading to a denial of<br />
service.  Ubuntu 6.06 was not affected. (CVE-2009-4031)<br />
<br />
It was discovered that the OHCI fireware driver did not correctly<br />
handle certain ioctls.  A local attacker could exploit this to crash<br />
the system, or possibly gain root privileges.  Ubuntu 6.06 was not<br />
affected. (CVE-2009-4138)<br />
<br />
Tavis Orm<br />
[...]<br />
<br />
Solution :<br />
<br />
Upgrade to : <br />
- linux-doc-2.6.31-19.56 (Ubuntu 9.10)<br />
- linux-doc-2.6.15-2.6.15-55.82 (Ubuntu 6.06)<br />
- linux-doc-2.6.24-2.6.24-27.65 (Ubuntu 8.04)<br />
- linux-doc-2.6.27-2.6.27-17.45 (Ubuntu 8.10)<br />
- linux-doc-2.6.28-2.6.28-18.59 (Ubuntu 9.04)<br />
- linux-ec2-doc-2.6.31-304.10 (Ubuntu 9.10)<br />
- linux-ec2-source-2.6.31-2.6.31-304.10 (Ubuntu 9.10)<br />
- linux-headers-2.6.15-55-2.6.15-55.82 (Ubuntu 6.06)<br />
- linux-headers-2.6.15-55-386-2.6.15-55.82 (Ubuntu 6.06)<br />
- linux-headers-2.6.15-55-686-2.6.15-55.82 (Ubuntu 6.06)<br />
- linux-h<br />
[...]<br />
<br />
Risk factor :<br />
<br />
Critical / CVSS Base Score : 10.0<br />
(CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)<br />
]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=44399</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=44398">
<title>SuSE Security Update:  Security update for Linux kernel (kernel-6806)</title>
<description><![CDATA[Synopsis :<br />
<br />
The remote SuSE system is missing the security patch kernel-6806<br />
<br />
Description :<br />
<br />
This update fixes a several security issues and various bugs in the SUSE Linux<br />
Enterprise 10 SP 2 kernel.<br />
<br />
<br />
<br />
The following security issues were fixed:<br />
<br />
<br />
<br />
 CVE-2009-3556: Two sysfs filers in the qla2xxx driver were worldwriteable,<br />
so users could change SCSI attributes of the qla2xxx driver.<br />
 CVE-2009-4536: drivers/net/e1000/e1000_main.c in the e1000 driver in the<br />
Linux kernel handles Ethernet frames that exceed the MTU by processing<br />
certain trailing payload data as if it were a complete frame, which<br />
allows remote attackers to bypass packet filters via a large packet with<br />
a crafted payload.<br />
<br />
<br />
<br />
(The e1000e driver is not included in the SLES 10 SP2 kernel, so CVE-2009-4538<br />
does not affect this kernel.)<br />
<br />
Solution :<br />
<br />
Install the security patch kernel-6806<br />
<br />
Risk factor :<br />
<br />
Critical / CVSS Base Score : 10.0<br />
(CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)<br />
]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=44398</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=44397">
<title>Solaris Unbundled (sparc) : 138195-03</title>
<description><![CDATA[Synopsis :<br />
<br />
The remote host is missing Sun Security Patch number 138195-03<br />
<br />
Description :<br />
<br />
Service Tags 1.0: patch for Solaris 10.<br />
Date this patch was last updated by Sun : Feb/04/10<br />
<br />
See also :<br />
<br />
<a href="http://sunsolve.sun.com/search/document.do?assetkey=1-21-138195-03-1" target="_blank">http://sunsolve.sun.com/search/document.do?assetkey=1-21-138195-03-1</a><br />
<br />
Solution :<br />
<br />
You should install this patch for your system to be up-to-date.<br />
<br />
Risk factor :<br />
<br />
High<br />
]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=44397</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=44396">
<title>MDVSA-2010:032: rootcerts</title>
<description><![CDATA[Synopsis :<br />
<br />
The remote host is missing the patch for the advisory MDVSA-2010:032 (rootcerts).<br />
<br />
Description :<br />
<br />
It was brought to our attention by Ludwig Nussel at SUSE the md5<br />
collision certificate should not be included. This update removes<br />
the offending certificate.<br />
Packages for 2008.0 are provided for Corporate Desktop 2008.0<br />
customers.<br />
The mozilla nss library has consequently been rebuilt to pickup these<br />
changes and are also being provided.<br />
<br />
See also :<br />
<br />
<a href="http://wwwnew.mandriva.com/security/advisories?name=MDVSA-2010:032" target="_blank">http://wwwnew.mandriva.com/security/advisories?name=MDVSA-2010:032</a><br />
<br />
Solution :<br />
<br />
Apply the newest security patches from Mandriva.<br />
<br />
Risk factor :<br />
<br />
High<br />
]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=44396</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=44395">
<title>CentOS : RHSA-2010-0076</title>
<description><![CDATA[Synopsis :<br />
<br />
The remote host is missing a security update.<br />
<br />
Description :<br />
<br />
The remote CentOS system is missing a security update which has been <br />
documented in Red Hat advisory RHSA-2010-0076.<br />
<br />
See also :<br />
<br />
<a href="https://rhn.redhat.com/errata/RHSA-2010-0076.html" target="_blank">https://rhn.redhat.com/errata/RHSA-2010-0076.html</a><br />
<br />
Solution :<br />
<br />
Upgrade to the newest packages by doing :<br />
<br />
  yum update<br />
<br />
Risk factor :<br />
<br />
High / CVSS Base Score : 7.8<br />
(CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C)<br />
]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=44395</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=44394">
<title>IBM Tivoli Monitoring Service Console Detection</title>
<description><![CDATA[Synopsis :<br />
<br />
A system monitoring console was detected on the remote web server.<br />
<br />
Description :<br />
<br />
Tivoli Monitoring Service Console, a web interface for running system<br />
diagnostics, is hosted on the remote web server.  This software is<br />
included with some IBM products, such as DB2.<br />
<br />
See also :<br />
<br />
<a href="http://www.ibm.com/software/tivoli/products/monitor/" target="_blank">http://www.ibm.com/software/tivoli/products/monitor/</a><br />
<br />
Solution :<br />
<br />
n/a<br />
<br />
Risk factor :<br />
<br />
None<br />
]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=44394</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=44393">
<title>OCS Inventory NG Server Administration Console header.php login Parameter SQL Injection</title>
<description><![CDATA[Synopsis :<br />
<br />
The remote web server is hosting a PHP application that is vulnerable<br />
to a SQL-injection attack.<br />
<br />
Description :<br />
<br />
The version of the OCS Inventory NG Server Administration Console<br />
hosted on the remote web server fails to properly sanitize user<br />
supplied input to the 'login' parameter of the 'header.php' script. <br />
<br />
Provided PHP's 'magic_quotes_gpc' setting is disabled, an attacker can<br />
exploit this to bypass authentication and thereby gain access to the<br />
administrative interface.<br />
<br />
See also :<br />
<br />
<a href="http://www.securityfocus.com/archive/1/509252/30/0/threaded" target="_blank">http://www.securityfocus.com/archive/1/509252/30/0/threaded</a><br />
<a href="http://forums.ocsinventory-ng.org/viewtopic.php?id=5609" target="_blank">http://forums.ocsinventory-ng.org/viewtopic.php?id=5609</a><br />
<br />
Solution :<br />
<br />
Upgrade to OCS Inventory NG Management Server version 1.3beta4 /<br />
1.02.2 or later as those versions have been determined to address the<br />
vulnerability.<br />
<br />
Risk factor :<br />
<br />
High / CVSS Base Score : 7.5<br />
(CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P)<br />
]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=44393</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=44392">
<title>OCS Inventory NG Server Administration Console Detection</title>
<description><![CDATA[Synopsis :<br />
<br />
The remote web server is hosting an asset management application<br />
written in PHP.<br />
<br />
Description :<br />
<br />
The remote web server is hosting the OCS Inventory NG Server<br />
Administration console, a PHP application for managing computing<br />
assets.<br />
<br />
See also :<br />
<br />
<a href="http://www.ocsinventory-ng.org/" target="_blank">http://www.ocsinventory-ng.org/</a><br />
<br />
Solution :<br />
<br />
n/a<br />
<br />
Risk factor :<br />
<br />
None<br />
]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=44392</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=44391">
<title>Linksys Router Detection</title>
<description><![CDATA[Synopsis :<br />
<br />
The remote device is a Linksys router.<br />
<br />
Description :<br />
<br />
The remote device is a Linksys router.  These devices route packets<br />
and may provide port forwarding, DMZ configuration and other<br />
networking services.<br />
<br />
See also :<br />
<br />
<a href="http://www.linksysbycisco.com/" target="_blank">http://www.linksysbycisco.com/</a><br />
<br />
Solution :<br />
<br />
Ensure that use of this device agrees with your organization's<br />
acceptable use and security policies.<br />
<br />
Risk factor :<br />
<br />
None<br />
]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=44391</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=44390">
<title>FreeBSD : apache -- Prevent chunk-size integer overflow on platforms where sizeof(int) &amp;lt; sizeof(long) (5219)</title>
<description><![CDATA[Synopsis :<br />
<br />
The remote host is missing a security update<br />
<br />
Description :<br />
<br />
The following package needs to be updated: apache+ipv6<br />
<br />
See also :<br />
<br />
<a href="http://security-tracker.debian.org/tracker/CVE-2010-0010" target="_blank">http://security-tracker.debian.org/tracker/CVE-2010-0010</a><br />
<a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-0010" target="_blank">http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-0010</a><br />
<a href="http://www.security-database.com/detail.php?alert=CVE-2010-0010" target="_blank">http://www.security-database.com/detail.php?alert=CVE-2010-0010</a><br />
<a href="http://www.vupen.com/english/Reference-CVE-2010-0010.php" target="_blank">http://www.vupen.com/english/Reference-CVE-2010-0010.php</a><br />
<a href="http://www.FreeBSD.org/ports/portaudit/cae01d7b-110d-11df-955a-00219b0fc4d8.html" target="_blank">http://www.FreeBSD.org/ports/portaudit/cae01d7b-110d-11df-955a-00219b0fc4d8.html</a><br />
<br />
Solution :<br />
<br />
Update the package on the remote host<br />
<br />
Risk factor :<br />
<br />
High<br />
]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=44390</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=44389">
<title>SuSE Security Update:  fuse (2010-01-26)</title>
<description><![CDATA[Synopsis :<br />
<br />
The remote SuSE system is missing a security patch for fuse<br />
<br />
Description :<br />
<br />
A race condition in fusermount allowed users to umount any filesystem (CVE-2009-3297). This has been fixed.<br />
<br />
See also :<br />
<br />
<a href="https://bugzilla.novell.com/show_bug.cgi?id=550003" target="_blank">https://bugzilla.novell.com/show_bug.cgi?id=550003</a><br />
<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3297" target="_blank">http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3297</a><br />
<br />
Solution :<br />
<br />
Run yast to install the security patch for fuse<br />
<br />
Risk factor :<br />
<br />
High<br />
]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=44389</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=44388">
<title>Solaris 10 (x86) : 140160-02</title>
<description><![CDATA[Synopsis :<br />
<br />
The remote host is missing Sun Security Patch number 140160-02<br />
<br />
Description :<br />
<br />
SunOS 5.10_x86: rsh/rlogin/rcp/rdist patch.<br />
Date this patch was last updated by Sun : Feb/02/10<br />
<br />
See also :<br />
<br />
<a href="http://sunsolve.sun.com/search/document.do?assetkey=1-21-140160-02-1" target="_blank">http://sunsolve.sun.com/search/document.do?assetkey=1-21-140160-02-1</a><br />
<br />
Solution :<br />
<br />
You should install this patch for your system to be up-to-date.<br />
<br />
Risk factor :<br />
<br />
High<br />
]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=44388</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=44387">
<title>Solaris 10 (sparc) : 140159-02</title>
<description><![CDATA[Synopsis :<br />
<br />
The remote host is missing Sun Security Patch number 140159-02<br />
<br />
Description :<br />
<br />
SunOS 5.10: rsh/rlogin/rcp/rdist patch.<br />
Date this patch was last updated by Sun : Feb/02/10<br />
<br />
See also :<br />
<br />
<a href="http://sunsolve.sun.com/search/document.do?assetkey=1-21-140159-02-1" target="_blank">http://sunsolve.sun.com/search/document.do?assetkey=1-21-140159-02-1</a><br />
<br />
Solution :<br />
<br />
You should install this patch for your system to be up-to-date.<br />
<br />
Risk factor :<br />
<br />
High<br />
]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=44387</link>
<dc:date>?</dc:date>
</item>
</rdf:RDF>
