Author: chandra
Date: 2008-10-06 13:07:14 +0200 (Mon, 06 Oct 2008)
New Revision: 1487
Added:
trunk/openvas-plugins/scripts/gb_firefox_detect_win.nasl
trunk/openvas-plugins/scripts/gb_firefox_mult_vuln_july08_win.nasl
trunk/openvas-plugins/scripts/gb_seamonkey_detect_win.nasl
trunk/openvas-plugins/scripts/gb_seamonkey_mult_vuln_july08_win.nasl
trunk/openvas-plugins/scripts/gb_thunderbird_detect_win.nasl
trunk/openvas-plugins/scripts/gb_thunderbird_mult_vuln_july08_win.nasl
Modified:
trunk/openvas-plugins/ChangeLog
Log:
Added new plugins
Modified: trunk/openvas-plugins/ChangeLog
===================================================================
--- trunk/openvas-plugins/ChangeLog 2008-10-05 10:04:08 UTC (rev 1486)
+++ trunk/openvas-plugins/ChangeLog 2008-10-06 11:07:14 UTC (rev 1487)
@@ -1,3 +1,12 @@
+2008-10-06 Chandrashekhar B <[EMAIL PROTECTED]>
+ * scripts/gb_thunderbird_detect_win.nasl,
+ scripts/gb_thunderbird_mult_vuln_july08_win.nasl,
+ scripts/gb_firefox_detect_win.nasl,
+ scripts/gb_firefox_mult_vuln_july08_win.nasl,
+ scripts/gb_seamonkey_detect_win.nasl,
+ scripts/gb_seamonkey_mult_vuln_july08_win.nasl:
+ Added new plugins
+
2008-10-04 Chandrashekhar B <[EMAIL PROTECTED]>
* scripts/gb_adobe_prdts_code_exec_vuln_lin.nasl,
scripts/gb_adobe_prdts_detect_lin.nasl:
Added: trunk/openvas-plugins/scripts/gb_firefox_detect_win.nasl
===================================================================
--- trunk/openvas-plugins/scripts/gb_firefox_detect_win.nasl 2008-10-05
10:04:08 UTC (rev 1486)
+++ trunk/openvas-plugins/scripts/gb_firefox_detect_win.nasl 2008-10-06
11:07:14 UTC (rev 1487)
@@ -0,0 +1,143 @@
+###############################################################################
+# OpenVAS Vulnerability Test
+# $Id: gb_firefox_detect_win.nasl 302 2008-10-03 16:07:35Z oct $
+#
+# Mozilla Firefox Version Detection (Windows)
+#
+# Authors:
+# Chandan S <[EMAIL PROTECTED]>
+#
+# Copyright:
+# Copyright (c) 2008 Intevation GmbH, http://www.intevation.net
+#
+# This program is free software; you can redistribute it and/or modify
+# it under the terms of the GNU General Public License version 2
+# (or any later version), as published by the Free Software Foundation.
+#
+# This program is distributed in the hope that it will be useful,
+# but WITHOUT ANY WARRANTY; without even the implied warranty of
+# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
+# GNU General Public License for more details.
+#
+# You should have received a copy of the GNU General Public License
+# along with this program; if not, write to the Free Software
+# Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
+###############################################################################
+
+if(description)
+{
+ script_id(800014);
+ script_version("Revision: 1.0 ");
+ script_name(english:"Mozilla Firefox Version Detection (Windows)");
+ desc["english"] = "
+ Overview : This script finds the Mozilla Firefox installed version on
Windows
+ and save the version in KB.
+
+ Risk factor : Informational";
+
+ script_description(english:desc["english"]);
+ script_summary(english:"Set Version of Mozilla Firefox in KB");
+ script_category(ACT_GATHER_INFO);
+ script_copyright(english:"Copyright (C) 2008 Intevation GmbH");
+ script_family(english:"General");
+ script_dependencies("secpod_reg_enum.nasl");
+ script_require_keys("SMB/WindowsVersion");
+ exit(0);
+}
+
+
+include("smb_nt.inc");
+include("secpod_smb_func.inc");
+
+if(!get_kb_item("SMB/WindowsVersion")){
+ exit(0);
+}
+
+# Check for Firefox browser
+foxVer = registry_get_sz(key:"SOFTWARE\Mozilla\Mozilla Firefox",
+ item:"CurrentVersion");
+if(foxVer)
+{
+ # Check other than Firefox Version 1.5
+ if("1.5" >!< foxVer){
+ foxVer = eregmatch(pattern:"[0-9.]+", string:foxVer);
+ set_kb_item(name:"Firefox/Win/Ver", value:foxVer[0]);
+ }
+
+ # Detect Firefox Version 1.5.x series
+ if("1.5" >< foxVer)
+ {
+ exeFile = registry_get_sz(key:"SOFTWARE\Microsoft\Windows\Current" +
+ "Version\Uninstall\Mozilla Firefox (1.5)",
+ item:"InstallLocation");
+ if(exeFile == NULL)
+ {
+ close(soc);
+ exit(0);
+ }
+
+ share = ereg_replace(pattern:"([A-Z]):.*", replace:"\1$", string:exeFile);
+ file = ereg_replace(pattern:"[A-Z]:(.*)", replace:"\1",
+ string:exeFile + "\firefox.exe");
+
+ soc = open_sock_tcp(port);
+ if(!soc){
+ exit(0);
+ }
+
+ r = smb_session_request(soc:soc, remote:name);
+ if(!r){
+ close(soc);
+ exit(0);
+ }
+
+ prot = smb_neg_prot(soc:soc);
+ if(!prot){
+ close(soc);
+ exit(0);
+ }
+
+ r = smb_session_setup(soc:soc, login:login, password:pass, domain:domain,
+ prot:prot);
+ if(!r){
+ close(soc);
+ exit(0);
+ }
+
+ uid = session_extract_uid(reply:r);
+ if(!uid){
+ close(soc);
+ exit(0);
+ }
+
+ r = smb_tconx(soc:soc, name:name, uid:uid, share:share);
+ tid = tconx_extract_tid(reply:r);
+ if(!tid){
+ close(soc);
+ exit(0);
+ }
+
+ fid = OpenAndX(socket:soc, uid:uid, tid:tid, file:file);
+ if(!fid){
+ close(soc);
+ exit(0);
+ }
+
+ fileVer = GetVersion(socket:soc, uid:uid, tid:tid, fid:fid, verstr:"prod",
+ offset:260000);
+ close(soc);
+ if(fileVer){
+ set_kb_item(name:"Firefox/Win/Ver",value:fileVer);
+ }
+ }
+}
+else
+{
+ foxVer = registry_get_sz(key:"SOFTWARE\mozilla.org\Mozilla Firefox",
+ item:"CurrentVersion");
+ if(foxVer)
+ {
+ foxVer = eregmatch(pattern:"[0-9.]+", string:foxVer);
+ set_kb_item(name:"Firefox/Win/Ver", value:foxVer[0]);
+ }
+}
Added: trunk/openvas-plugins/scripts/gb_firefox_mult_vuln_july08_win.nasl
===================================================================
--- trunk/openvas-plugins/scripts/gb_firefox_mult_vuln_july08_win.nasl
2008-10-05 10:04:08 UTC (rev 1486)
+++ trunk/openvas-plugins/scripts/gb_firefox_mult_vuln_july08_win.nasl
2008-10-06 11:07:14 UTC (rev 1487)
@@ -0,0 +1,107 @@
+###############################################################################
+# OpenVAS Vulnerability Test
+# $Id: gb_firefox_mult_vuln_july08_win.nasl 302 2008-10-03 12:37:36Z oct $
+#
+# Mozilla Firefox Multiple Vulnerability July-08 (Win)
+#
+# Authors:
+# Chandan S <[EMAIL PROTECTED]>
+#
+# Copyright:
+# Copyright (c) 2008 Intevation GmbH, http://www.intevation.net
+#
+# This program is free software; you can redistribute it and/or modify
+# it under the terms of the GNU General Public License version 2
+# (or any later version), as published by the Free Software Foundation.
+#
+# This program is distributed in the hope that it will be useful,
+# but WITHOUT ANY WARRANTY; without even the implied warranty of
+# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
+# GNU General Public License for more details.
+#
+# You should have received a copy of the GNU General Public License
+# along with this program; if not, write to the Free Software
+# Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
+###############################################################################
+
+if(description)
+{
+ script_id(800011);
+ script_version("$Revision: 1.1 $");
+ script_cve_id("CVE-2008-2798", "CVE-2008-2799", "CVE-2008-2800",
"CVE-2008-2801",
+ "CVE-2008-2802", "CVE-2008-2803", "CVE-2008-2805",
"CVE-2008-2806",
+ "CVE-2008-2807", "CVE-2008-2808", "CVE-2008-2809",
"CVE-2008-2810",
+ "CVE-2008-2811");
+ script_bugtraq_id(30038);
+ script_xref(name:"CB-A", value:"08-0109");
+ script_name(english:"Mozilla Firefox Multiple Vulnerability July-08 (Win)");
+ desc["english"] = "
+
+ Overview : The host is installed with Mozilla Firefox browser, that is prone
+ to multiple vulnerabilities.
+
+ Vulnerability Insight:
+ Issues in browser are due to,
+ - multiple errors in the layout and JavaScript engines that can corrupt
+ memory.
+ - error while handling unprivileged XUL documents that can be exploited to
+ load chrome scripts from a fastload file via <script> elements.
+ - error in mozIJSSubScriptLoader.LoadScript function can bypass
+ XPCNativeWrappers.
+ - error in block re-flow process, which can potentially lead to crash.
+ - error in processing file URLs contained within local directory listings.
+ - errors in the implementation of the Javascript same origin policy
+ - errors in the verification of signed JAR files.
+ - improper implementation of file upload forms result in uploading specially
+ crafted DOM Range and originalTarget elements.
+ - error in Java LiveConnect implementation.
+ - error in processing of Alt Names provided by peer.
+ - error in processing of windows URL shortcuts.
+
+ Impact:
+ Successful exploitation could result in remote arbitrary code execution,
+ spoofing attacks, sensitive information disclosure, and JavaScript code can
+ be executed with the privileges of JAR's signer.
+
+ Impact Level: System
+
+ Affected Software/OS:
+ Firefox version prior to 2.0.0.15 on Windows.
+
+ Fix: Upgrade to Firefox version 2.0.0.15
+ http://www.mozilla.com/en-US/firefox/all-older.html
+
+ References :
+ http://www.mozilla.org/security/announce/2008/mfsa2008-21.html
+ http://www.mozilla.org/security/announce/2008/mfsa2008-22.html
+ http://www.mozilla.org/security/announce/2008/mfsa2008-23.html
+ http://www.mozilla.org/security/announce/2008/mfsa2008-24.html
+ http://www.mozilla.org/security/announce/2008/mfsa2008-25.html
+ http://www.mozilla.org/security/announce/2008/mfsa2008-27.html
+ http://www.mozilla.org/security/announce/2008/mfsa2008-28.html
+ http://www.mozilla.org/security/announce/2008/mfsa2008-29.html
+ http://www.mozilla.org/security/announce/2008/mfsa2008-30.html
+ http://www.mozilla.org/security/announce/2008/mfsa2008-31.html
+ http://www.mozilla.org/security/announce/2008/mfsa2008-32.html
+ http://www.mozilla.org/security/announce/2008/mfsa2008-33.html
+
+ CVSS Score:
+ CVSS Base Score : 9.3 (AV:N/AC:M/Au:NR/C:C/I:C/A:C)
+ CVSS Temporal Score : 6.9
+ Risk factor : High";
+
+ script_description(english:desc["english"]);
+ script_summary(english:"Check for the version of Firefox");
+ script_category(ACT_GATHER_INFO);
+ script_copyright(english:"Copyright (C) 2008 Intevation GmbH");
+ script_family(english:"Misc.");
+ script_dependencies("gb_firefox_detect_win.nasl");
+ exit(0);
+}
+
+
+# Grep for firefox version < 2.0.0.15
+if(egrep(pattern:"^([01]\..*|2\.0(\.0\.(0?[0-9]|1[0-4]))?)$",
+ string:get_kb_item("Firefox/Win/Ver"))){
+ security_hole(0);
+}
Property changes on:
trunk/openvas-plugins/scripts/gb_firefox_mult_vuln_july08_win.nasl
___________________________________________________________________
Name: svn:executable
+ *
Added: trunk/openvas-plugins/scripts/gb_seamonkey_detect_win.nasl
===================================================================
--- trunk/openvas-plugins/scripts/gb_seamonkey_detect_win.nasl 2008-10-05
10:04:08 UTC (rev 1486)
+++ trunk/openvas-plugins/scripts/gb_seamonkey_detect_win.nasl 2008-10-06
11:07:14 UTC (rev 1487)
@@ -0,0 +1,63 @@
+###############################################################################
+# OpenVAS Vulnerability Test
+# $Id: gb_seamonkey_detect_win.nasl 302 2008-10-03 14:07:35Z oct $
+#
+# Mozilla Seamonkey Version Detection (Windows)
+#
+# Authors:
+# Chandan S <[EMAIL PROTECTED]>
+#
+# Copyright:
+# Copyright (c) 2008 Intevation GmbH, http://www.intevation.net
+#
+# This program is free software; you can redistribute it and/or modify
+# it under the terms of the GNU General Public License version 2
+# (or any later version), as published by the Free Software Foundation.
+#
+# This program is distributed in the hope that it will be useful,
+# but WITHOUT ANY WARRANTY; without even the implied warranty of
+# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
+# GNU General Public License for more details.
+#
+# You should have received a copy of the GNU General Public License
+# along with this program; if not, write to the Free Software
+# Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
+###############################################################################
+
+
+if(description)
+{
+ script_id(800016);
+ script_version("Revision: 1.0 ");
+ script_name(english:"Mozilla SeaMonkey Version Detection (Windows)");
+ desc["english"] = "
+ Overview : This script finds the Mozilla SeaMonkey installed version on
+ Windows and save the version in KB.
+
+ Risk factor : Informational";
+
+ script_description(english:desc["english"]);
+ script_summary(english:"Set Version of Mozilla SeaMonkey in KB");
+ script_category(ACT_GATHER_INFO);
+ script_copyright(english:"Copyright (C) 2008 SecPod");
+ script_family(english:"General");
+ script_dependencies("secpod_reg_enum.nasl");
+ script_require_keys("SMB/WindowsVersion");
+ exit(0);
+}
+
+
+include("smb_nt.inc");
+
+if(!get_kb_item("SMB/WindowsVersion")){
+ exit(0);
+}
+
+# Check for SeaMonkey version through Registry entry
+seaVer = registry_get_sz(key:"SOFTWARE\mozilla.org\SeaMonkey",
+ item:"CurrentVersion");
+if(seaVer)
+{
+ seaVer = eregmatch(pattern:"[0-9.]+", string:seaVer);
+ set_kb_item(name:"Seamonkey/Win/Ver", value:seaVer[0]);
+}
Added: trunk/openvas-plugins/scripts/gb_seamonkey_mult_vuln_july08_win.nasl
===================================================================
--- trunk/openvas-plugins/scripts/gb_seamonkey_mult_vuln_july08_win.nasl
2008-10-05 10:04:08 UTC (rev 1486)
+++ trunk/openvas-plugins/scripts/gb_seamonkey_mult_vuln_july08_win.nasl
2008-10-06 11:07:14 UTC (rev 1487)
@@ -0,0 +1,107 @@
+###############################################################################
+# OpenVAS Vulnerability Test
+# $Id: gb_seamonkey_mult_vuln_july08_win.nasl 302 2008-10-03 17:07:35Z oct $
+#
+# Mozilla Seamonkey Multiple Vulnerability July-08 (Win)
+#
+# Authors:
+# Chandan S <[EMAIL PROTECTED]>
+#
+# Copyright:
+# Copyright (c) 2008 Intevation GmbH, http://www.intevation.net
+#
+# This program is free software; you can redistribute it and/or modify
+# it under the terms of the GNU General Public License version 2
+# (or any later version), as published by the Free Software Foundation.
+#
+# This program is distributed in the hope that it will be useful,
+# but WITHOUT ANY WARRANTY; without even the implied warranty of
+# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
+# GNU General Public License for more details.
+#
+# You should have received a copy of the GNU General Public License
+# along with this program; if not, write to the Free Software
+# Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
+###############################################################################
+
+if(description)
+{
+ script_id(800013);
+ script_version("$Revision: 1.1 $");
+ script_cve_id("CVE-2008-2798", "CVE-2008-2799", "CVE-2008-2800",
"CVE-2008-2801",
+ "CVE-2008-2802", "CVE-2008-2803", "CVE-2008-2805",
"CVE-2008-2806",
+ "CVE-2008-2807", "CVE-2008-2808", "CVE-2008-2809",
"CVE-2008-2810",
+ "CVE-2008-2811");
+ script_bugtraq_id(30038);
+ script_xref(name:"CB-A", value:"08-0109");
+ script_name(english:"Mozilla Seamonkey Multiple Vulnerability July-08
(Win)");
+ desc["english"] = "
+
+ Overview : The host is installed with Mozilla Seamonkey, that is prone to
+ multiple vulnerabilities.
+
+ Vulnerability Insight:
+ Issues are due to,
+ - multiple errors in the layout and JavaScript engines that can corrupt
+ memory.
+ - error while handling unprivileged XUL documents that can be exploited
+ to load chrome scripts from a fastload file via <script> elements.
+ - error in mozIJSSubScriptLoader.LoadScript function can bypass
+ XPCNativeWrappers.
+ - error in block re-flow process, which can potentially lead to crash.
+ - error in processing file URLs contained within local directory listings.
+ - errors in the implementation of the Javascript same origin policy
+ - errors in the verification of signed JAR files.
+ - improper implementation of file upload forms result in uploading specially
+ crafted DOM Range and originalTarget elements.
+ - error in Java LiveConnect implementation.
+ - error in processing of Alt Names provided by peer.
+ - error in processing of windows URL shortcuts.
+
+ Impact:
+ Successful exploitation could result in remote arbitrary code execution,
+ spoofing attacks, sensitive information disclosure, and JavaScript code can
+ execute with the privileges of JAR's signer.
+
+ Impact Level: System
+
+ Affected Software/OS:
+ Seamonkey version prior to 1.1.10 on Windows.
+
+ Fix: Upgrade to Seamonkey version 1.1.10 or later
+ http://www.seamonkey-project.org/releases/
+
+ References:
+ http://www.mozilla.org/security/announce/2008/mfsa2008-21.html
+ http://www.mozilla.org/security/announce/2008/mfsa2008-22.html
+ http://www.mozilla.org/security/announce/2008/mfsa2008-23.html
+ http://www.mozilla.org/security/announce/2008/mfsa2008-24.html
+ http://www.mozilla.org/security/announce/2008/mfsa2008-25.html
+ http://www.mozilla.org/security/announce/2008/mfsa2008-27.html
+ http://www.mozilla.org/security/announce/2008/mfsa2008-28.html
+ http://www.mozilla.org/security/announce/2008/mfsa2008-29.html
+ http://www.mozilla.org/security/announce/2008/mfsa2008-30.html
+ http://www.mozilla.org/security/announce/2008/mfsa2008-31.html
+ http://www.mozilla.org/security/announce/2008/mfsa2008-32.html
+ http://www.mozilla.org/security/announce/2008/mfsa2008-33.html
+
+ CVSS Score:
+ CVSS Base Score : 9.3 (AV:N/AC:M/Au:NR/C:C/I:C/A:C)
+ CVSS Temporal Score : 6.9
+ Risk factor : High";
+
+ script_description(english:desc["english"]);
+ script_summary(english:"Check for the version of Seamonkey");
+ script_category(ACT_GATHER_INFO);
+ script_copyright(english:"Copyright (C) 2008 Intevation GmbH");
+ script_family(english:"Misc.");
+ script_dependencies("gb_seamonkey_detect_win.nasl");
+ exit(0);
+}
+
+
+# Grep for seamonkey version < 1.1.10
+if(egrep(pattern:"^(0\..*|1\.0(\..*)?|1\.1(\.0?[0-9]))$",
+ string:get_kb_item("Seamonkey/Win/Ver"))){
+ security_hole(0);
+}
Property changes on:
trunk/openvas-plugins/scripts/gb_seamonkey_mult_vuln_july08_win.nasl
___________________________________________________________________
Name: svn:executable
+ *
Added: trunk/openvas-plugins/scripts/gb_thunderbird_detect_win.nasl
===================================================================
--- trunk/openvas-plugins/scripts/gb_thunderbird_detect_win.nasl
2008-10-05 10:04:08 UTC (rev 1486)
+++ trunk/openvas-plugins/scripts/gb_thunderbird_detect_win.nasl
2008-10-06 11:07:14 UTC (rev 1487)
@@ -0,0 +1,136 @@
+###############################################################################
+# OpenVAS Vulnerability Test
+# $Id: gb_thunderbird_detect_win.nasl 302 2008-10-03 14:23:34Z oct $
+#
+# Mozilla Thunderbird Version Detection (Windows)
+#
+# Authors:
+# Chandan S <[EMAIL PROTECTED]>
+#
+# Copyright:
+# Copyright (c) 2008 Intevation GmbH, http://www.intevation.net
+#
+# This program is free software; you can redistribute it and/or modify
+# it under the terms of the GNU General Public License version 2
+# (or any later version), as published by the Free Software Foundation.
+#
+# This program is distributed in the hope that it will be useful,
+# but WITHOUT ANY WARRANTY; without even the implied warranty of
+# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
+# GNU General Public License for more details.
+#
+# You should have received a copy of the GNU General Public License
+# along with this program; if not, write to the Free Software
+# Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
+###############################################################################
+
+
+if(description)
+{
+ script_id(800015);
+ script_version("Revision: 1.0 ");
+ script_name(english:"Mozilla Thunderbird Version Detection (Windows)");
+ desc["english"] = "
+ Overview : This script retrieves Mozilla ThunderBird Version and
+ saves it in KB.
+
+ Risk factor : Informational";
+
+ script_description(english:desc["english"]);
+ script_summary(english:"Set Version of Mozilla Thunderbird in KB");
+ script_category(ACT_GATHER_INFO);
+ script_copyright(english:"Copyright (C) 2008 Intevation GmbH");
+ script_family(english:"General");
+ script_dependencies("secpod_reg_enum.nasl");
+ script_require_keys("SMB/WindowsVersion");
+ exit(0);
+}
+
+
+include("smb_nt.inc");
+include("secpod_smb_func.inc");
+
+if(!get_kb_item("SMB/WindowsVersion")){ # Confirm it is Windows
+ exit(0);
+}
+
+# Get ThunderBird Version from Registry
+birdVer = registry_get_sz(item:"CurrentVersion",
+ key:"SOFTWARE\Mozilla\Mozilla Thunderbird");
+if(!birdVer){
+ exit(0);
+}
+
+if(!ereg(pattern:"1\.5[^.0-9]", string:birdVer))
+{
+ birdVer = eregmatch(pattern:"[0-9.]+", string:birdVer);
+ set_kb_item(name:"Thunderbird/Win/Ver",value:birdVer[0]);
+ exit(0);
+}
+
+# Special case for thunderbird 1.5 (Get the version from file)
+if("1.5" >< birdVer)
+{
+ filePath = registry_get_sz(item:"PathToExe",
+ key:"SOFTWARE\Mozilla\Mozilla Thunderbird
1.5\bin");
+ if(!filePath){
+ exit(0);
+ }
+
+ share = ereg_replace(pattern:"([A-Z]):.*", replace:"\1$", string:filePath);
+ file = ereg_replace(pattern:"[A-Z]:(.*)", replace:"\1", string:filePath);
+
+ soc = open_sock_tcp(port);
+ if(!soc){
+ exit(0);
+ }
+
+ r = smb_session_request(soc:soc, remote:name);
+ if(!r){
+ close(soc);
+ exit(0);
+ }
+
+ prot = smb_neg_prot(soc:soc);
+ if(!prot){
+ close(soc);
+ exit(0);
+ }
+
+ r = smb_session_setup(soc:soc, login:login, password:pass, domain:domain,
prot:prot);
+ if(!r){
+ close(soc);
+ exit(0);
+ }
+
+ uid = session_extract_uid(reply:r);
+ r = smb_tconx(soc:soc, name:name, uid:uid, share:share);
+ tid = tconx_extract_tid(reply:r);
+ if(!tid){
+ close(soc);
+ exit(0);
+ }
+
+ fid = OpenAndX(socket:soc, uid:uid, tid:tid, file:file);
+ if(!fid){
+ close(soc);
+ exit(0);
+ }
+
+ fileVer = GetVersion(socket:soc, uid:uid, tid:tid, fid:fid,
+ offset:260000, verstr="prod");
+ close(soc);
+ if(fileVer){
+ set_kb_item(name:"Thunderbird/Win/Ver",value:fileVer);
+ }
+}
+else
+{
+ birdVer = registry_get_sz(item:"CurrentVersion",
+ key:"SOFTWARE\mozilla.org\Mozilla Thunderbird");
+ if(birdVer)
+ {
+ birdVer = eregmatch(pattern:"[0-9.]+", string:birdVer);
+ set_kb_item(name:"Thunderbird/Win/Ver",value:birdVer[0]);
+ }
+}
Property changes on:
trunk/openvas-plugins/scripts/gb_thunderbird_detect_win.nasl
___________________________________________________________________
Name: svn:executable
+ *
Added: trunk/openvas-plugins/scripts/gb_thunderbird_mult_vuln_july08_win.nasl
===================================================================
--- trunk/openvas-plugins/scripts/gb_thunderbird_mult_vuln_july08_win.nasl
2008-10-05 10:04:08 UTC (rev 1486)
+++ trunk/openvas-plugins/scripts/gb_thunderbird_mult_vuln_july08_win.nasl
2008-10-06 11:07:14 UTC (rev 1487)
@@ -0,0 +1,92 @@
+###############################################################################
+# OpenVAS Vulnerability Test
+# $Id: gb_thunderbird_mult_vuln_july08_win.nasl 302 2008-10-03 15:23:34Z oct $
+#
+# Mozilla Thunderbird Multiple Vulnerability July-08 (Win)
+#
+# Authors:
+# Chandan S <[EMAIL PROTECTED]>
+#
+# Copyright:
+# Copyright (c) 2008 Intevation GmbH, http://www.intevation.net
+#
+# This program is free software; you can redistribute it and/or modify
+# it under the terms of the GNU General Public License version 2
+# (or any later version), as published by the Free Software Foundation.
+#
+# This program is distributed in the hope that it will be useful,
+# but WITHOUT ANY WARRANTY; without even the implied warranty of
+# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
+# GNU General Public License for more details.
+#
+# You should have received a copy of the GNU General Public License
+# along with this program; if not, write to the Free Software
+# Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
+###############################################################################
+
+if(description)
+{
+ script_id(800012);
+ script_version("$Revision: 1.1 $");
+ script_cve_id("CVE-2008-2798", "CVE-2008-2799", "CVE-2008-2802",
"CVE-2008-2803",
+ "CVE-2008-2807", "CVE-2008-2809", "CVE-2008-2811");
+ script_bugtraq_id(30038);
+ script_xref(name:"CB-A", value:"08-0109");
+ script_name(english:"Mozilla Thunderbird Multiple Vulnerability July-08
(Win)");
+ desc["english"] = "
+
+ Overview : The host is installed with Mozilla Thunderbird, that
+ is prone to multiple vulnerabilities.
+
+ Vulnerability Insight:
+ The issues are due to,
+ - multiple errors in the layout and JavaScript engines that can corrupt
+ memory.
+ - error while handling unprivileged XUL documents that can be exploited to
load
+ chrome scripts from a fastload file via <script> elements.
+ - error in mozIJSSubScriptLoader.LoadScript function that can bypass
+ XPCNativeWrappers.
+ - error in block re-flow process, which can potentially lead to crash.
+ - errors in the implementation of the Javascript same origin policy
+ - error in processing of Alt Names provided by peer.
+ - error in processing of windows URL shortcuts.
+
+ Impact: Successful exploitation could result in remote arbitrary code
execution,
+ spoofing attacks, sensitive information disclosure, and can crash the
browser.
+
+ Impact Level : System
+
+ Affected Software/OS :
+ Thunderbird version prior to 2.0.0.16 on Windows.
+
+ Fix: Upgrade to Thunderbird version 2.0.0.16
+ http://www.mozilla.com/en-US/thunderbird/all-older.html
+
+ References :
+ http://www.mozilla.org/security/announce/2008/mfsa2008-21.html
+ http://www.mozilla.org/security/announce/2008/mfsa2008-24.html
+ http://www.mozilla.org/security/announce/2008/mfsa2008-25.html
+ http://www.mozilla.org/security/announce/2008/mfsa2008-29.html
+ http://www.mozilla.org/security/announce/2008/mfsa2008-31.html
+ http://www.mozilla.org/security/announce/2008/mfsa2008-33.html
+
+ CVSS Score:
+ CVSS Base Score : 9.3 (AV:N/AC:M/Au:NR/C:C/I:C/A:C)
+ CVSS Temporal Score : 6.9
+ Risk factor : High";
+
+ script_description(english:desc["english"]);
+ script_summary(english:"Check for the version of Thunderbird");
+ script_category(ACT_GATHER_INFO);
+ script_copyright(english:"Copyright (C) 2008 Intevation GmbH");
+ script_family(english:"Misc.");
+ script_dependencies("gb_thunderbird_detect_win.nasl");
+ exit(0);
+}
+
+
+# Grep for thunderbird version < 2.0.0.16
+if(egrep(pattern:"^([01]\..*|2\.0(\.0\.(0?[0-9]|1[0-5]))?)$",
+ string:get_kb_item("Thunderbird/Win/Ver"))){
+ security_hole(0);
+}
Property changes on:
trunk/openvas-plugins/scripts/gb_thunderbird_mult_vuln_july08_win.nasl
___________________________________________________________________
Name: svn:executable
+ *
_______________________________________________
Openvas-commits mailing list
[email protected]
http://lists.wald.intevation.org/mailman/listinfo/openvas-commits