Author: chandra
Date: 2008-10-06 13:07:14 +0200 (Mon, 06 Oct 2008)
New Revision: 1487

Added:
   trunk/openvas-plugins/scripts/gb_firefox_detect_win.nasl
   trunk/openvas-plugins/scripts/gb_firefox_mult_vuln_july08_win.nasl
   trunk/openvas-plugins/scripts/gb_seamonkey_detect_win.nasl
   trunk/openvas-plugins/scripts/gb_seamonkey_mult_vuln_july08_win.nasl
   trunk/openvas-plugins/scripts/gb_thunderbird_detect_win.nasl
   trunk/openvas-plugins/scripts/gb_thunderbird_mult_vuln_july08_win.nasl
Modified:
   trunk/openvas-plugins/ChangeLog
Log:
Added new plugins

Modified: trunk/openvas-plugins/ChangeLog
===================================================================
--- trunk/openvas-plugins/ChangeLog     2008-10-05 10:04:08 UTC (rev 1486)
+++ trunk/openvas-plugins/ChangeLog     2008-10-06 11:07:14 UTC (rev 1487)
@@ -1,3 +1,12 @@
+2008-10-06 Chandrashekhar B <[EMAIL PROTECTED]>
+       * scripts/gb_thunderbird_detect_win.nasl,
+         scripts/gb_thunderbird_mult_vuln_july08_win.nasl,
+         scripts/gb_firefox_detect_win.nasl,
+         scripts/gb_firefox_mult_vuln_july08_win.nasl,
+         scripts/gb_seamonkey_detect_win.nasl,
+         scripts/gb_seamonkey_mult_vuln_july08_win.nasl:
+         Added new plugins
+
 2008-10-04 Chandrashekhar B <[EMAIL PROTECTED]>
        * scripts/gb_adobe_prdts_code_exec_vuln_lin.nasl,
          scripts/gb_adobe_prdts_detect_lin.nasl:

Added: trunk/openvas-plugins/scripts/gb_firefox_detect_win.nasl
===================================================================
--- trunk/openvas-plugins/scripts/gb_firefox_detect_win.nasl    2008-10-05 
10:04:08 UTC (rev 1486)
+++ trunk/openvas-plugins/scripts/gb_firefox_detect_win.nasl    2008-10-06 
11:07:14 UTC (rev 1487)
@@ -0,0 +1,143 @@
+###############################################################################
+# OpenVAS Vulnerability Test
+# $Id: gb_firefox_detect_win.nasl 302 2008-10-03 16:07:35Z oct $
+#
+# Mozilla Firefox Version Detection (Windows)
+#
+# Authors:
+# Chandan S <[EMAIL PROTECTED]>
+#
+# Copyright:
+# Copyright (c) 2008 Intevation GmbH, http://www.intevation.net
+#
+# This program is free software; you can redistribute it and/or modify
+# it under the terms of the GNU General Public License version 2
+# (or any later version), as published by the Free Software Foundation.
+#
+# This program is distributed in the hope that it will be useful,
+# but WITHOUT ANY WARRANTY; without even the implied warranty of
+# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
+# GNU General Public License for more details.
+#
+# You should have received a copy of the GNU General Public License
+# along with this program; if not, write to the Free Software
+# Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
+###############################################################################
+
+if(description)
+{
+  script_id(800014);
+  script_version("Revision: 1.0 ");
+  script_name(english:"Mozilla Firefox Version Detection (Windows)");
+  desc["english"] = "
+  Overview : This script finds the Mozilla Firefox installed version on 
Windows 
+  and save the version in KB.
+
+  Risk factor : Informational";
+
+  script_description(english:desc["english"]);
+  script_summary(english:"Set Version of Mozilla Firefox in KB");
+  script_category(ACT_GATHER_INFO);
+  script_copyright(english:"Copyright (C) 2008 Intevation GmbH");
+  script_family(english:"General");
+  script_dependencies("secpod_reg_enum.nasl");
+  script_require_keys("SMB/WindowsVersion");
+  exit(0);
+}
+
+
+include("smb_nt.inc");
+include("secpod_smb_func.inc");
+
+if(!get_kb_item("SMB/WindowsVersion")){
+  exit(0);
+}
+
+# Check for Firefox browser
+foxVer = registry_get_sz(key:"SOFTWARE\Mozilla\Mozilla Firefox",
+                         item:"CurrentVersion");
+if(foxVer)
+{
+  # Check other than Firefox Version 1.5
+  if("1.5" >!< foxVer){
+     foxVer = eregmatch(pattern:"[0-9.]+", string:foxVer);
+     set_kb_item(name:"Firefox/Win/Ver", value:foxVer[0]);
+  }
+
+  # Detect Firefox Version 1.5.x series
+  if("1.5" >< foxVer)
+  {
+    exeFile  =  registry_get_sz(key:"SOFTWARE\Microsoft\Windows\Current" +
+                                    "Version\Uninstall\Mozilla Firefox (1.5)",
+                                item:"InstallLocation");
+    if(exeFile == NULL)
+    {
+      close(soc);
+      exit(0);
+    }
+
+    share = ereg_replace(pattern:"([A-Z]):.*", replace:"\1$", string:exeFile);
+    file = ereg_replace(pattern:"[A-Z]:(.*)", replace:"\1",
+                        string:exeFile + "\firefox.exe");
+
+    soc = open_sock_tcp(port);
+    if(!soc){
+      exit(0);
+    }
+
+    r = smb_session_request(soc:soc, remote:name);
+    if(!r){
+      close(soc);
+      exit(0);
+    }
+
+    prot = smb_neg_prot(soc:soc);
+    if(!prot){
+      close(soc);
+      exit(0);
+    }
+
+    r = smb_session_setup(soc:soc, login:login, password:pass, domain:domain,
+                          prot:prot);
+    if(!r){
+      close(soc);
+      exit(0);
+    }
+
+    uid = session_extract_uid(reply:r);
+    if(!uid){
+      close(soc);
+      exit(0);
+    }
+
+    r = smb_tconx(soc:soc, name:name, uid:uid, share:share);
+    tid = tconx_extract_tid(reply:r);
+    if(!tid){
+      close(soc);
+      exit(0);
+    }
+
+    fid = OpenAndX(socket:soc, uid:uid, tid:tid, file:file);
+    if(!fid){
+      close(soc);
+      exit(0);
+    }
+
+    fileVer = GetVersion(socket:soc, uid:uid, tid:tid, fid:fid, verstr:"prod",
+                         offset:260000);
+    close(soc);
+    if(fileVer){
+      set_kb_item(name:"Firefox/Win/Ver",value:fileVer);
+    }
+  }
+}
+else
+{
+  foxVer = registry_get_sz(key:"SOFTWARE\mozilla.org\Mozilla Firefox",
+                           item:"CurrentVersion");
+  if(foxVer)
+  {
+    foxVer = eregmatch(pattern:"[0-9.]+", string:foxVer);
+    set_kb_item(name:"Firefox/Win/Ver", value:foxVer[0]);
+  }
+}

Added: trunk/openvas-plugins/scripts/gb_firefox_mult_vuln_july08_win.nasl
===================================================================
--- trunk/openvas-plugins/scripts/gb_firefox_mult_vuln_july08_win.nasl  
2008-10-05 10:04:08 UTC (rev 1486)
+++ trunk/openvas-plugins/scripts/gb_firefox_mult_vuln_july08_win.nasl  
2008-10-06 11:07:14 UTC (rev 1487)
@@ -0,0 +1,107 @@
+###############################################################################
+# OpenVAS Vulnerability Test
+# $Id: gb_firefox_mult_vuln_july08_win.nasl 302 2008-10-03 12:37:36Z oct $
+#
+# Mozilla Firefox Multiple Vulnerability July-08 (Win)
+#
+# Authors:
+# Chandan S <[EMAIL PROTECTED]>
+#
+# Copyright:
+# Copyright (c) 2008 Intevation GmbH, http://www.intevation.net
+#
+# This program is free software; you can redistribute it and/or modify
+# it under the terms of the GNU General Public License version 2
+# (or any later version), as published by the Free Software Foundation.
+#
+# This program is distributed in the hope that it will be useful,
+# but WITHOUT ANY WARRANTY; without even the implied warranty of
+# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
+# GNU General Public License for more details.
+#
+# You should have received a copy of the GNU General Public License
+# along with this program; if not, write to the Free Software
+# Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
+###############################################################################
+
+if(description)
+{
+  script_id(800011);
+  script_version("$Revision: 1.1 $");
+  script_cve_id("CVE-2008-2798", "CVE-2008-2799", "CVE-2008-2800", 
"CVE-2008-2801",
+                "CVE-2008-2802", "CVE-2008-2803", "CVE-2008-2805", 
"CVE-2008-2806",
+                "CVE-2008-2807", "CVE-2008-2808", "CVE-2008-2809", 
"CVE-2008-2810",
+                "CVE-2008-2811");
+  script_bugtraq_id(30038);
+  script_xref(name:"CB-A", value:"08-0109");
+  script_name(english:"Mozilla Firefox Multiple Vulnerability July-08 (Win)");
+  desc["english"] = "
+
+  Overview : The host is installed with Mozilla Firefox browser, that is prone
+  to multiple vulnerabilities.
+
+  Vulnerability Insight:
+  Issues in browser are due to,
+  - multiple errors in the layout and JavaScript engines that can corrupt
+    memory.
+  - error while handling unprivileged XUL documents that can be exploited to
+    load chrome scripts from a fastload file via <script> elements.
+  - error in mozIJSSubScriptLoader.LoadScript function can bypass
+    XPCNativeWrappers.
+  - error in block re-flow process, which can potentially lead to crash.
+  - error in processing file URLs contained within local directory listings.
+  - errors in the implementation of the Javascript same origin policy
+  - errors in the verification of signed JAR files.
+  - improper implementation of file upload forms result in uploading specially
+    crafted DOM Range and originalTarget elements.
+  - error in Java LiveConnect implementation.
+  - error in processing of Alt Names provided by peer.
+  - error in processing of windows URL shortcuts.
+
+  Impact:
+  Successful exploitation could result in remote arbitrary code execution,
+  spoofing attacks, sensitive information disclosure, and JavaScript code can
+  be executed with the privileges of JAR's signer.
+  
+  Impact Level: System
+
+  Affected Software/OS:
+  Firefox version prior to 2.0.0.15 on Windows.
+
+  Fix: Upgrade to Firefox version 2.0.0.15
+  http://www.mozilla.com/en-US/firefox/all-older.html
+
+  References :
+  http://www.mozilla.org/security/announce/2008/mfsa2008-21.html
+  http://www.mozilla.org/security/announce/2008/mfsa2008-22.html
+  http://www.mozilla.org/security/announce/2008/mfsa2008-23.html
+  http://www.mozilla.org/security/announce/2008/mfsa2008-24.html
+  http://www.mozilla.org/security/announce/2008/mfsa2008-25.html
+  http://www.mozilla.org/security/announce/2008/mfsa2008-27.html
+  http://www.mozilla.org/security/announce/2008/mfsa2008-28.html
+  http://www.mozilla.org/security/announce/2008/mfsa2008-29.html
+  http://www.mozilla.org/security/announce/2008/mfsa2008-30.html
+  http://www.mozilla.org/security/announce/2008/mfsa2008-31.html
+  http://www.mozilla.org/security/announce/2008/mfsa2008-32.html
+  http://www.mozilla.org/security/announce/2008/mfsa2008-33.html
+
+  CVSS Score:
+    CVSS Base Score     : 9.3 (AV:N/AC:M/Au:NR/C:C/I:C/A:C)
+    CVSS Temporal Score : 6.9
+  Risk factor : High";
+
+  script_description(english:desc["english"]);
+  script_summary(english:"Check for the version of Firefox");
+  script_category(ACT_GATHER_INFO);
+  script_copyright(english:"Copyright (C) 2008 Intevation GmbH");
+  script_family(english:"Misc.");
+  script_dependencies("gb_firefox_detect_win.nasl");
+  exit(0);
+}
+
+
+# Grep for firefox version < 2.0.0.15
+if(egrep(pattern:"^([01]\..*|2\.0(\.0\.(0?[0-9]|1[0-4]))?)$",
+         string:get_kb_item("Firefox/Win/Ver"))){
+  security_hole(0);
+}


Property changes on: 
trunk/openvas-plugins/scripts/gb_firefox_mult_vuln_july08_win.nasl
___________________________________________________________________
Name: svn:executable
   + *

Added: trunk/openvas-plugins/scripts/gb_seamonkey_detect_win.nasl
===================================================================
--- trunk/openvas-plugins/scripts/gb_seamonkey_detect_win.nasl  2008-10-05 
10:04:08 UTC (rev 1486)
+++ trunk/openvas-plugins/scripts/gb_seamonkey_detect_win.nasl  2008-10-06 
11:07:14 UTC (rev 1487)
@@ -0,0 +1,63 @@
+###############################################################################
+# OpenVAS Vulnerability Test
+# $Id: gb_seamonkey_detect_win.nasl 302 2008-10-03 14:07:35Z oct $
+#
+# Mozilla Seamonkey Version Detection (Windows)
+#
+# Authors:
+# Chandan S <[EMAIL PROTECTED]>
+#
+# Copyright:
+# Copyright (c) 2008 Intevation GmbH, http://www.intevation.net
+#
+# This program is free software; you can redistribute it and/or modify
+# it under the terms of the GNU General Public License version 2
+# (or any later version), as published by the Free Software Foundation.
+#
+# This program is distributed in the hope that it will be useful,
+# but WITHOUT ANY WARRANTY; without even the implied warranty of
+# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
+# GNU General Public License for more details.
+#
+# You should have received a copy of the GNU General Public License
+# along with this program; if not, write to the Free Software
+# Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
+###############################################################################
+
+
+if(description)
+{
+  script_id(800016);
+  script_version("Revision: 1.0 ");
+  script_name(english:"Mozilla SeaMonkey Version Detection (Windows)");
+  desc["english"] = "
+  Overview : This script finds the Mozilla SeaMonkey installed version on 
+  Windows and save the version in KB.
+
+  Risk factor : Informational";
+
+  script_description(english:desc["english"]);
+  script_summary(english:"Set Version of Mozilla SeaMonkey in KB");
+  script_category(ACT_GATHER_INFO);
+  script_copyright(english:"Copyright (C) 2008 SecPod");
+  script_family(english:"General");
+  script_dependencies("secpod_reg_enum.nasl");
+  script_require_keys("SMB/WindowsVersion");
+  exit(0);
+}
+
+
+include("smb_nt.inc");
+
+if(!get_kb_item("SMB/WindowsVersion")){
+  exit(0);
+}
+
+# Check for SeaMonkey version through Registry entry
+seaVer = registry_get_sz(key:"SOFTWARE\mozilla.org\SeaMonkey",
+                         item:"CurrentVersion");
+if(seaVer)
+{
+  seaVer = eregmatch(pattern:"[0-9.]+", string:seaVer);
+  set_kb_item(name:"Seamonkey/Win/Ver", value:seaVer[0]);
+}

Added: trunk/openvas-plugins/scripts/gb_seamonkey_mult_vuln_july08_win.nasl
===================================================================
--- trunk/openvas-plugins/scripts/gb_seamonkey_mult_vuln_july08_win.nasl        
2008-10-05 10:04:08 UTC (rev 1486)
+++ trunk/openvas-plugins/scripts/gb_seamonkey_mult_vuln_july08_win.nasl        
2008-10-06 11:07:14 UTC (rev 1487)
@@ -0,0 +1,107 @@
+###############################################################################
+# OpenVAS Vulnerability Test
+# $Id: gb_seamonkey_mult_vuln_july08_win.nasl 302 2008-10-03 17:07:35Z oct $
+#
+# Mozilla Seamonkey Multiple Vulnerability July-08 (Win)
+#
+# Authors:
+# Chandan S <[EMAIL PROTECTED]>
+#
+# Copyright:
+# Copyright (c) 2008 Intevation GmbH, http://www.intevation.net
+#
+# This program is free software; you can redistribute it and/or modify
+# it under the terms of the GNU General Public License version 2
+# (or any later version), as published by the Free Software Foundation.
+#
+# This program is distributed in the hope that it will be useful,
+# but WITHOUT ANY WARRANTY; without even the implied warranty of
+# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
+# GNU General Public License for more details.
+#
+# You should have received a copy of the GNU General Public License
+# along with this program; if not, write to the Free Software
+# Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
+###############################################################################
+
+if(description)
+{
+  script_id(800013);
+  script_version("$Revision: 1.1 $");
+  script_cve_id("CVE-2008-2798", "CVE-2008-2799", "CVE-2008-2800", 
"CVE-2008-2801",
+                "CVE-2008-2802", "CVE-2008-2803", "CVE-2008-2805", 
"CVE-2008-2806",
+                "CVE-2008-2807", "CVE-2008-2808", "CVE-2008-2809", 
"CVE-2008-2810",
+                "CVE-2008-2811");
+  script_bugtraq_id(30038);
+  script_xref(name:"CB-A", value:"08-0109");
+  script_name(english:"Mozilla Seamonkey Multiple Vulnerability July-08 
(Win)");
+  desc["english"] = "
+
+  Overview : The host is installed with Mozilla Seamonkey, that is prone to
+  multiple vulnerabilities.
+
+  Vulnerability Insight:
+  Issues are due to,
+  - multiple errors in the layout and JavaScript engines that can corrupt
+    memory.
+  - error while handling unprivileged XUL documents that can be exploited
+    to load chrome scripts from a fastload file via <script> elements.
+  - error in mozIJSSubScriptLoader.LoadScript function can bypass
+    XPCNativeWrappers.
+  - error in block re-flow process, which can potentially lead to crash.
+  - error in processing file URLs contained within local directory listings.
+  - errors in the implementation of the Javascript same origin policy
+  - errors in the verification of signed JAR files.
+  - improper implementation of file upload forms result in uploading specially
+    crafted DOM Range and originalTarget elements.
+  - error in Java LiveConnect implementation.
+  - error in processing of Alt Names provided by peer.
+  - error in processing of windows URL shortcuts.
+
+  Impact:
+  Successful exploitation could result in remote arbitrary code execution,
+  spoofing attacks, sensitive information disclosure, and JavaScript code can
+  execute with the privileges of JAR's signer.
+  
+  Impact Level: System
+
+  Affected Software/OS:
+  Seamonkey version prior to 1.1.10 on Windows.
+
+  Fix: Upgrade to Seamonkey version 1.1.10 or later
+  http://www.seamonkey-project.org/releases/
+
+  References:
+  http://www.mozilla.org/security/announce/2008/mfsa2008-21.html
+  http://www.mozilla.org/security/announce/2008/mfsa2008-22.html
+  http://www.mozilla.org/security/announce/2008/mfsa2008-23.html
+  http://www.mozilla.org/security/announce/2008/mfsa2008-24.html
+  http://www.mozilla.org/security/announce/2008/mfsa2008-25.html
+  http://www.mozilla.org/security/announce/2008/mfsa2008-27.html
+  http://www.mozilla.org/security/announce/2008/mfsa2008-28.html
+  http://www.mozilla.org/security/announce/2008/mfsa2008-29.html
+  http://www.mozilla.org/security/announce/2008/mfsa2008-30.html
+  http://www.mozilla.org/security/announce/2008/mfsa2008-31.html
+  http://www.mozilla.org/security/announce/2008/mfsa2008-32.html
+  http://www.mozilla.org/security/announce/2008/mfsa2008-33.html
+
+  CVSS Score:
+    CVSS Base Score     : 9.3 (AV:N/AC:M/Au:NR/C:C/I:C/A:C)
+    CVSS Temporal Score : 6.9
+  Risk factor : High";
+
+  script_description(english:desc["english"]);
+  script_summary(english:"Check for the version of Seamonkey");
+  script_category(ACT_GATHER_INFO);
+  script_copyright(english:"Copyright (C) 2008 Intevation GmbH");
+  script_family(english:"Misc.");
+  script_dependencies("gb_seamonkey_detect_win.nasl");
+  exit(0);
+}
+
+
+# Grep for seamonkey version < 1.1.10
+if(egrep(pattern:"^(0\..*|1\.0(\..*)?|1\.1(\.0?[0-9]))$",
+         string:get_kb_item("Seamonkey/Win/Ver"))){
+  security_hole(0);
+}


Property changes on: 
trunk/openvas-plugins/scripts/gb_seamonkey_mult_vuln_july08_win.nasl
___________________________________________________________________
Name: svn:executable
   + *

Added: trunk/openvas-plugins/scripts/gb_thunderbird_detect_win.nasl
===================================================================
--- trunk/openvas-plugins/scripts/gb_thunderbird_detect_win.nasl        
2008-10-05 10:04:08 UTC (rev 1486)
+++ trunk/openvas-plugins/scripts/gb_thunderbird_detect_win.nasl        
2008-10-06 11:07:14 UTC (rev 1487)
@@ -0,0 +1,136 @@
+###############################################################################
+# OpenVAS Vulnerability Test
+# $Id: gb_thunderbird_detect_win.nasl 302 2008-10-03 14:23:34Z oct $
+#
+# Mozilla Thunderbird Version Detection (Windows)
+#
+# Authors:
+# Chandan S <[EMAIL PROTECTED]>
+#
+# Copyright:
+# Copyright (c) 2008 Intevation GmbH, http://www.intevation.net
+#
+# This program is free software; you can redistribute it and/or modify
+# it under the terms of the GNU General Public License version 2
+# (or any later version), as published by the Free Software Foundation.
+#
+# This program is distributed in the hope that it will be useful,
+# but WITHOUT ANY WARRANTY; without even the implied warranty of
+# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
+# GNU General Public License for more details.
+#
+# You should have received a copy of the GNU General Public License
+# along with this program; if not, write to the Free Software
+# Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
+###############################################################################
+
+
+if(description)
+{
+  script_id(800015);
+  script_version("Revision: 1.0 ");
+  script_name(english:"Mozilla Thunderbird Version Detection (Windows)");
+  desc["english"] = "
+  Overview : This script retrieves Mozilla ThunderBird Version and
+  saves it in KB.
+
+  Risk factor : Informational";
+
+  script_description(english:desc["english"]);
+  script_summary(english:"Set Version of Mozilla Thunderbird in KB");
+  script_category(ACT_GATHER_INFO);
+  script_copyright(english:"Copyright (C) 2008 Intevation GmbH");
+  script_family(english:"General");
+  script_dependencies("secpod_reg_enum.nasl");
+  script_require_keys("SMB/WindowsVersion");
+  exit(0);
+}
+
+
+include("smb_nt.inc");
+include("secpod_smb_func.inc");
+
+if(!get_kb_item("SMB/WindowsVersion")){ # Confirm it is Windows
+  exit(0);
+}
+
+# Get ThunderBird Version from Registry
+birdVer = registry_get_sz(item:"CurrentVersion", 
+                          key:"SOFTWARE\Mozilla\Mozilla Thunderbird");
+if(!birdVer){
+  exit(0);
+}
+
+if(!ereg(pattern:"1\.5[^.0-9]", string:birdVer))
+{
+  birdVer = eregmatch(pattern:"[0-9.]+", string:birdVer);
+  set_kb_item(name:"Thunderbird/Win/Ver",value:birdVer[0]);
+  exit(0);
+}
+
+# Special case for thunderbird 1.5 (Get the version from file)
+if("1.5" >< birdVer)
+{
+  filePath = registry_get_sz(item:"PathToExe",
+                             key:"SOFTWARE\Mozilla\Mozilla Thunderbird 
1.5\bin");
+  if(!filePath){
+    exit(0);
+  }
+
+  share = ereg_replace(pattern:"([A-Z]):.*", replace:"\1$", string:filePath);
+  file =  ereg_replace(pattern:"[A-Z]:(.*)", replace:"\1", string:filePath);
+
+  soc = open_sock_tcp(port);
+  if(!soc){
+    exit(0);
+  }
+
+  r = smb_session_request(soc:soc, remote:name);
+  if(!r){
+    close(soc);
+    exit(0);
+  }
+
+  prot = smb_neg_prot(soc:soc);
+  if(!prot){
+    close(soc);
+    exit(0);
+  }
+
+  r = smb_session_setup(soc:soc, login:login, password:pass, domain:domain, 
prot:prot);
+  if(!r){
+    close(soc);
+    exit(0);
+  }
+
+  uid = session_extract_uid(reply:r);
+  r = smb_tconx(soc:soc, name:name, uid:uid, share:share);
+  tid = tconx_extract_tid(reply:r);
+  if(!tid){
+    close(soc);
+    exit(0);
+  }
+
+  fid = OpenAndX(socket:soc, uid:uid, tid:tid, file:file);
+  if(!fid){
+    close(soc);
+    exit(0);
+  }
+
+  fileVer = GetVersion(socket:soc, uid:uid, tid:tid, fid:fid,
+                       offset:260000, verstr="prod");
+  close(soc);
+  if(fileVer){
+    set_kb_item(name:"Thunderbird/Win/Ver",value:fileVer);
+  }
+}
+else
+{
+  birdVer = registry_get_sz(item:"CurrentVersion", 
+                            key:"SOFTWARE\mozilla.org\Mozilla Thunderbird");
+  if(birdVer)
+  {
+    birdVer = eregmatch(pattern:"[0-9.]+", string:birdVer);
+    set_kb_item(name:"Thunderbird/Win/Ver",value:birdVer[0]);
+  }
+}


Property changes on: 
trunk/openvas-plugins/scripts/gb_thunderbird_detect_win.nasl
___________________________________________________________________
Name: svn:executable
   + *

Added: trunk/openvas-plugins/scripts/gb_thunderbird_mult_vuln_july08_win.nasl
===================================================================
--- trunk/openvas-plugins/scripts/gb_thunderbird_mult_vuln_july08_win.nasl      
2008-10-05 10:04:08 UTC (rev 1486)
+++ trunk/openvas-plugins/scripts/gb_thunderbird_mult_vuln_july08_win.nasl      
2008-10-06 11:07:14 UTC (rev 1487)
@@ -0,0 +1,92 @@
+###############################################################################
+# OpenVAS Vulnerability Test
+# $Id: gb_thunderbird_mult_vuln_july08_win.nasl 302 2008-10-03 15:23:34Z oct $
+#
+# Mozilla Thunderbird Multiple Vulnerability July-08 (Win)
+#
+# Authors:
+# Chandan S <[EMAIL PROTECTED]>
+#
+# Copyright:
+# Copyright (c) 2008 Intevation GmbH, http://www.intevation.net
+#
+# This program is free software; you can redistribute it and/or modify
+# it under the terms of the GNU General Public License version 2
+# (or any later version), as published by the Free Software Foundation.
+#
+# This program is distributed in the hope that it will be useful,
+# but WITHOUT ANY WARRANTY; without even the implied warranty of
+# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
+# GNU General Public License for more details.
+#
+# You should have received a copy of the GNU General Public License
+# along with this program; if not, write to the Free Software
+# Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
+###############################################################################
+
+if(description)
+{
+  script_id(800012);
+  script_version("$Revision: 1.1 $");
+  script_cve_id("CVE-2008-2798", "CVE-2008-2799", "CVE-2008-2802", 
"CVE-2008-2803",
+                "CVE-2008-2807", "CVE-2008-2809", "CVE-2008-2811");
+  script_bugtraq_id(30038);
+  script_xref(name:"CB-A", value:"08-0109");
+  script_name(english:"Mozilla Thunderbird Multiple Vulnerability July-08 
(Win)");
+  desc["english"] = "
+
+  Overview : The host is installed with Mozilla Thunderbird, that
+  is prone to multiple vulnerabilities.
+
+  Vulnerability Insight:
+  The issues are due to,
+  - multiple errors in the layout and JavaScript engines that can corrupt
+    memory.
+  - error while handling unprivileged XUL documents that can be exploited to 
load
+    chrome scripts from a fastload file via <script> elements.
+  - error in mozIJSSubScriptLoader.LoadScript function that can bypass
+    XPCNativeWrappers.
+  - error in block re-flow process, which can potentially lead to crash.
+  - errors in the implementation of the Javascript same origin policy
+  - error in processing of Alt Names provided by peer.
+  - error in processing of windows URL shortcuts.
+
+  Impact: Successful exploitation could result in remote arbitrary code 
execution,
+  spoofing attacks, sensitive information disclosure, and can crash the 
browser.
+  
+  Impact Level : System
+
+  Affected Software/OS :
+  Thunderbird version prior to 2.0.0.16 on Windows.
+
+  Fix: Upgrade to Thunderbird version 2.0.0.16
+  http://www.mozilla.com/en-US/thunderbird/all-older.html
+
+  References :
+  http://www.mozilla.org/security/announce/2008/mfsa2008-21.html
+  http://www.mozilla.org/security/announce/2008/mfsa2008-24.html
+  http://www.mozilla.org/security/announce/2008/mfsa2008-25.html
+  http://www.mozilla.org/security/announce/2008/mfsa2008-29.html
+  http://www.mozilla.org/security/announce/2008/mfsa2008-31.html
+  http://www.mozilla.org/security/announce/2008/mfsa2008-33.html
+
+  CVSS Score:
+    CVSS Base Score     : 9.3 (AV:N/AC:M/Au:NR/C:C/I:C/A:C)
+    CVSS Temporal Score : 6.9
+  Risk factor : High";
+
+  script_description(english:desc["english"]);
+  script_summary(english:"Check for the version of Thunderbird");
+  script_category(ACT_GATHER_INFO);
+  script_copyright(english:"Copyright (C) 2008 Intevation GmbH");
+  script_family(english:"Misc.");
+  script_dependencies("gb_thunderbird_detect_win.nasl");
+  exit(0);
+}
+
+
+# Grep for thunderbird version < 2.0.0.16
+if(egrep(pattern:"^([01]\..*|2\.0(\.0\.(0?[0-9]|1[0-5]))?)$",
+         string:get_kb_item("Thunderbird/Win/Ver"))){
+  security_hole(0);
+}


Property changes on: 
trunk/openvas-plugins/scripts/gb_thunderbird_mult_vuln_july08_win.nasl
___________________________________________________________________
Name: svn:executable
   + *

_______________________________________________
Openvas-commits mailing list
[email protected]
http://lists.wald.intevation.org/mailman/listinfo/openvas-commits

Reply via email to