Author: chandra
Date: 2008-10-07 14:21:23 +0200 (Tue, 07 Oct 2008)
New Revision: 1489

Added:
   trunk/openvas-plugins/scripts/gb_firefox_detect_lin.nasl
   trunk/openvas-plugins/scripts/gb_firefox_mult_vuln_july08_lin.nasl
   trunk/openvas-plugins/scripts/gb_seamonkey_detect_lin.nasl
   trunk/openvas-plugins/scripts/gb_seamonkey_mult_vuln_july08_lin.nasl
   trunk/openvas-plugins/scripts/gb_thunderbird_detect_lin.nasl
   trunk/openvas-plugins/scripts/gb_thunderbird_mult_vuln_july08_lin.nasl
Modified:
   trunk/openvas-plugins/ChangeLog
Log:
Added new plugins

Modified: trunk/openvas-plugins/ChangeLog
===================================================================
--- trunk/openvas-plugins/ChangeLog     2008-10-06 13:28:08 UTC (rev 1488)
+++ trunk/openvas-plugins/ChangeLog     2008-10-07 12:21:23 UTC (rev 1489)
@@ -1,3 +1,12 @@
+2008-10-07 Chandrashekhar B <[EMAIL PROTECTED]>
+       * scripts/gb_thunderbird_mult_vuln_july08_lin.nasl,
+         scripts/gb_seamonkey_mult_vuln_july08_lin.nasl,
+         scripts/gb_firefox_detect_lin.nasl,
+         scripts/gb_thunderbird_detect_lin.nasl,
+         scripts/gb_firefox_mult_vuln_july08_lin.nasl,
+         scripts/gb_seamonkey_detect_lin.nasl:
+         Added new plugins
+
 2008-10-06 Chandrashekhar B <[EMAIL PROTECTED]>
        * scripts/gb_thunderbird_detect_win.nasl,
          scripts/gb_thunderbird_mult_vuln_july08_win.nasl,

Added: trunk/openvas-plugins/scripts/gb_firefox_detect_lin.nasl
===================================================================
--- trunk/openvas-plugins/scripts/gb_firefox_detect_lin.nasl    2008-10-06 
13:28:08 UTC (rev 1488)
+++ trunk/openvas-plugins/scripts/gb_firefox_detect_lin.nasl    2008-10-07 
12:21:23 UTC (rev 1489)
@@ -0,0 +1,88 @@
+###############################################################################
+# OpenVAS Vulnerability Test
+# $Id: gb_firefox_detect_lin.nasl 302 2008-10-06 15:57:11Z oct $
+#
+# Mozilla Firefox Version Detection (Linux)
+#
+# Authors:
+# Chandan S <[EMAIL PROTECTED]>
+#
+# Copyright:
+# Copyright (c) 2008 Intevation GmbH, http://www.intevation.net
+#
+# This program is free software; you can redistribute it and/or modify
+# it under the terms of the GNU General Public License version 2
+# (or any later version), as published by the Free Software Foundation.
+#
+# This program is distributed in the hope that it will be useful,
+# but WITHOUT ANY WARRANTY; without even the implied warranty of
+# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
+# GNU General Public License for more details.
+#
+# You should have received a copy of the GNU General Public License
+# along with this program; if not, write to the Free Software
+# Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
+###############################################################################
+
+
+if(description)
+{
+  script_id(800017);
+  script_version("Revision: 1.1 ");
+  script_name(english:"Mozilla Firefox Version Detection (Linux)");
+  desc["english"] = "
+  Overview : This script finds the Mozilla Firefox installed version on Linux
+  and save the version in KB.
+
+  Risk factor : Informational";
+
+  script_description(english:desc["english"]);
+  script_family(english:"General");
+  script_category(ACT_GATHER_INFO);
+  script_copyright(english:"Copyright (C) 2008 Intevation GmbH");
+  script_summary(english:"Set File Version of Mozilla Firefox in KB");
+  exit(0);
+}
+
+
+include("ssh_func.inc");
+
+sock = ssh_login_or_reuse_connection();
+if(!sock){
+  exit(0);
+}
+
+foxName = ssh_cmd(socket:sock, cmd:"firefox -v", timeout:120);
+if(foxName =~ "firefox.* not found")
+{
+  foxName = ssh_cmd(socket:sock, cmd:"locate -ir firefox$", timeout:120);
+  if("firefox" >< foxName)
+  {
+    foxName = split(foxName);
+    for(i = 0; i < max_index(foxName); i++)
+      path = path + chomp(foxName[i]) + " -v;";
+
+    foxName = ssh_cmd(socket:sock, cmd:path, timeout:120);
+  }
+  else
+  {
+    # Search for Firefox thoroughly (slow).
+    if("yes" >< get_kb_item("global_settings/thorough_tests"))
+    {
+      command = "find / -mount -maxdepth 5 -mindepth 1 -type f -name " +
+                "'firefox' -exec '{}' '-v' ';'";
+      foxName = ssh_cmd(socket:sock, cmd:command, timeout:500);
+    }
+  }
+}
+
+# Firefox is branded as Iceweasel in Debian
+if(foxName =~ "Firefox|Iceweasel")
+{
+  foxName = egrep(pattern:"Mozilla.*Copyright.*mozilla\.org", string:foxName);
+  foxName = chomp(foxName);
+  foxVer = eregmatch(pattern:"[.0-9]+", string:foxName);
+  set_kb_item(name:"Firefox/Linux/Ver", value:foxVer[0]);
+}
+
+ssh_close_connection();

Added: trunk/openvas-plugins/scripts/gb_firefox_mult_vuln_july08_lin.nasl
===================================================================
--- trunk/openvas-plugins/scripts/gb_firefox_mult_vuln_july08_lin.nasl  
2008-10-06 13:28:08 UTC (rev 1488)
+++ trunk/openvas-plugins/scripts/gb_firefox_mult_vuln_july08_lin.nasl  
2008-10-07 12:21:23 UTC (rev 1489)
@@ -0,0 +1,107 @@
+###############################################################################
+# OpenVAS Vulnerability Test
+# $Id: gb_firefox_mult_vuln_july08_lin.nasl 302 2008-10-03 20:58:15Z oct $
+#
+# Mozilla Firefox Multiple Vulnerability July-08 (Linux)
+#
+# Authors:
+# Chandan S <[EMAIL PROTECTED]>
+#
+# Copyright:
+# Copyright (c) 2008 Intevation GmbH, http://www.intevation.net
+#
+# This program is free software; you can redistribute it and/or modify
+# it under the terms of the GNU General Public License version 2
+# (or any later version), as published by the Free Software Foundation.
+#
+# This program is distributed in the hope that it will be useful,
+# but WITHOUT ANY WARRANTY; without even the implied warranty of
+# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
+# GNU General Public License for more details.
+#
+# You should have received a copy of the GNU General Public License
+# along with this program; if not, write to the Free Software
+# Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
+###############################################################################
+
+if(description)
+{
+  script_id(800020);
+  script_version("$Revision: 1.1 $");
+  script_cve_id("CVE-2008-2798", "CVE-2008-2799", "CVE-2008-2800", 
"CVE-2008-2801",
+                "CVE-2008-2802", "CVE-2008-2803", "CVE-2008-2805", 
"CVE-2008-2806",
+                "CVE-2008-2807", "CVE-2008-2808", "CVE-2008-2809", 
"CVE-2008-2810",
+                "CVE-2008-2811");
+  script_bugtraq_id(30038);
+  script_xref(name:"CB-A", value:"08-0109");
+  script_name(english:"Mozilla Firefox Multiple Vulnerability July-08 
(Linux)");
+  desc["english"] = "
+
+  Overview: The host is installed with Mozilla Firefox browser, that is prone
+  to multiple vulnerabilities.
+
+  Vulnerability Insight:
+  Issues in browser are due to,
+  - multiple errors in the layout and JavaScript engines that can corrupt
+    memory.
+  - error while handling unprivileged XUL documents that can be exploited to
+    load chrome scripts from a fastload file via <script> elements.
+  - error in mozIJSSubScriptLoader.LoadScript function can bypass
+    XPCNativeWrappers.
+  - error in block re-flow process, which can potentially lead to crash.
+  - error in processing file URLs contained within local directory listings.
+  - errors in the implementation of the Javascript same origin policy
+  - errors in the verification of signed JAR files.
+  - improper implementation of file upload forms result in uploading specially
+    crafted DOM Range and originalTarget elements.
+  - error in Java LiveConnect implementation.
+  - error in processing of Alt Names provided by peer.
+  - error in processing of windows URL shortcuts.
+
+  Impact:
+  Successful exploitation could result in remote arbitrary code execution,
+  spoofing attacks, sensitive information disclosure, and JavaScript code can
+  be executed with the privileges of JAR's signer.
+
+  Impact Level: System
+
+  Affected Software/OS:
+  Firefox version prior to 2.0.0.15 on Linux.
+
+  Fix: Upgrade to Firefox version 2.0.0.15
+  http://www.mozilla.com/en-US/firefox/all-older.html
+
+  References :
+  http://www.mozilla.org/security/announce/2008/mfsa2008-21.html
+  http://www.mozilla.org/security/announce/2008/mfsa2008-22.html
+  http://www.mozilla.org/security/announce/2008/mfsa2008-23.html
+  http://www.mozilla.org/security/announce/2008/mfsa2008-24.html
+  http://www.mozilla.org/security/announce/2008/mfsa2008-25.html
+  http://www.mozilla.org/security/announce/2008/mfsa2008-27.html
+  http://www.mozilla.org/security/announce/2008/mfsa2008-28.html
+  http://www.mozilla.org/security/announce/2008/mfsa2008-29.html
+  http://www.mozilla.org/security/announce/2008/mfsa2008-30.html
+  http://www.mozilla.org/security/announce/2008/mfsa2008-31.html
+  http://www.mozilla.org/security/announce/2008/mfsa2008-32.html
+  http://www.mozilla.org/security/announce/2008/mfsa2008-33.html
+
+  CVSS Score:
+    CVSS Base Score     : 9.3 (AV:N/AC:M/Au:NR/C:C/I:C/A:C)
+    CVSS Temporal Score : 6.9
+  Risk factor : High";
+
+  script_description(english:desc["english"]);
+  script_summary(english:"Check for the version of Firefox");
+  script_category(ACT_GATHER_INFO);
+  script_copyright(english:"Copyright (C) 2008 Intevation GmbH");
+  script_family(english:"Misc.");
+  script_dependencies("gb_firefox_detect_lin.nasl");
+  exit(0);
+}
+
+
+# Grep for firefox version < 2.0.0.15
+if(egrep(pattern:"^([01]\..*|2\.0(\.0\.(0?[0-9]|1[0-4]))?)$",
+         string:get_kb_item("Firefox/Linux/Ver"))){
+  security_hole(0);
+}


Property changes on: 
trunk/openvas-plugins/scripts/gb_firefox_mult_vuln_july08_lin.nasl
___________________________________________________________________
Name: svn:executable
   + *

Added: trunk/openvas-plugins/scripts/gb_seamonkey_detect_lin.nasl
===================================================================
--- trunk/openvas-plugins/scripts/gb_seamonkey_detect_lin.nasl  2008-10-06 
13:28:08 UTC (rev 1488)
+++ trunk/openvas-plugins/scripts/gb_seamonkey_detect_lin.nasl  2008-10-07 
12:21:23 UTC (rev 1489)
@@ -0,0 +1,92 @@
+###############################################################################
+# OpenVAS Vulnerability Test
+# $Id: gb_seamonkey_detect_lin.nasl 302 2008-10-06 18:59:15Z oct $
+#
+# Mozilla Seamonkey Version Detection (Linux)
+#
+# Authors:
+# Chandan S <[EMAIL PROTECTED]>
+#
+# Copyright:
+# Copyright (c) 2008 Intevation GmbH, http://www.intevation.net
+#
+# This program is free software; you can redistribute it and/or modify
+# it under the terms of the GNU General Public License version 2
+# (or any later version), as published by the Free Software Foundation.
+#
+# This program is distributed in the hope that it will be useful,
+# but WITHOUT ANY WARRANTY; without even the implied warranty of
+# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
+# GNU General Public License for more details.
+#
+# You should have received a copy of the GNU General Public License
+# along with this program; if not, write to the Free Software
+# Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
+###############################################################################
+
+
+if(description)
+{
+  script_id(800019);
+  script_version("Revision: 1.1 ");
+  script_name(english:"Mozilla SeaMonkey Version Detection (Linux)");
+  desc["english"] = "
+  Overview : This script finds the Mozilla SeaMonkey installed version on
+  Linux and saves the version in KB.
+
+  Risk factor : Informational";
+
+  script_description(english:desc["english"]);
+  script_family(english:"General");
+  script_category(ACT_GATHER_INFO);
+  script_copyright(english:"Copyright (C) 2008 Intevation GmbH");
+  script_summary(english:"Set File Version of Mozilla SeaMonkey in KB");
+  exit(0);
+}
+
+
+include("ssh_func.inc");
+
+sock = ssh_login_or_reuse_connection();
+if(!sock){
+  exit(0);
+}
+
+seaName = ssh_cmd(socket:sock, cmd:"seamonkey -v", timeout:120);
+if(seaName =~ "seamonkey.* not found"){
+  seaName = ssh_cmd(socket:sock, cmd:"iceape -v", timeout:120);
+}
+
+if(seaName =~ "iceape.* not found")
+{
+  seaName = ssh_cmd(socket:sock, cmd:"locate -ir seamonkey$", timeout:120);
+  if("seamonkey" >< seaName)
+  {
+    seaName = split(seaName);
+    for(i = 0; i < max_index(seaName); i++)
+      path = path + chomp(seaName[i]) + " -v;";
+
+    seaName = ssh_cmd(socket:sock, cmd:path, timeout:120);
+  }
+  else
+  {
+    # Check for Seamonkey thoroughly (slow).
+    if("yes" >< get_kb_item("global_settings/thorough_tests"))
+    {
+      command = "find / -mount -maxdepth 5 -mindepth 1 -type f -name " +
+                "'seamonkey' -exec '{}' '-v' ';'";
+      seaName = ssh_cmd(socket:sock, cmd:command, timeout:500);
+    }
+  }
+}
+
+# Seamonkey is branded as Iceape in Debian
+if(seaName =~ "Seamonkey|Iceape")
+{
+  seaName = egrep(pattern:"(SeaMonkey|Iceape).*Copyright.*mozilla\.org", 
string:seaName);
+  seaName = chomp(seaName);
+  seaVer = eregmatch(pattern:"[.0-9]+", string:seaName);
+  set_kb_item(name:"Seamonkey/Linux/Ver", value:seaVer[0]);
+}
+
+ssh_close_connection();

Added: trunk/openvas-plugins/scripts/gb_seamonkey_mult_vuln_july08_lin.nasl
===================================================================
--- trunk/openvas-plugins/scripts/gb_seamonkey_mult_vuln_july08_lin.nasl        
2008-10-06 13:28:08 UTC (rev 1488)
+++ trunk/openvas-plugins/scripts/gb_seamonkey_mult_vuln_july08_lin.nasl        
2008-10-07 12:21:23 UTC (rev 1489)
@@ -0,0 +1,107 @@
+###############################################################################
+# OpenVAS Vulnerability Test
+# $Id: gb_seamonkey_mult_vuln_july08_lin.nasl 302 2008-10-03 21:03:20Z oct $
+#
+# Mozilla Seamonkey Multiple Vulnerability July-08 (Linux)
+#
+# Authors:
+# Chandan S <[EMAIL PROTECTED]>
+#
+# Copyright:
+# Copyright (c) 2008 Intevation GmbH, http://www.intevation.net
+#
+# This program is free software; you can redistribute it and/or modify
+# it under the terms of the GNU General Public License version 2
+# (or any later version), as published by the Free Software Foundation.
+#
+# This program is distributed in the hope that it will be useful,
+# but WITHOUT ANY WARRANTY; without even the implied warranty of
+# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
+# GNU General Public License for more details.
+#
+# You should have received a copy of the GNU General Public License
+# along with this program; if not, write to the Free Software
+# Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
+###############################################################################
+
+if(description)
+{
+  script_id(800022);
+  script_version("$Revision: 1.1 $");
+  script_cve_id("CVE-2008-2798", "CVE-2008-2799", "CVE-2008-2800", 
"CVE-2008-2801",
+                "CVE-2008-2802", "CVE-2008-2803", "CVE-2008-2805", 
"CVE-2008-2806",
+                "CVE-2008-2807", "CVE-2008-2808", "CVE-2008-2809", 
"CVE-2008-2810",
+                "CVE-2008-2811");
+  script_bugtraq_id(30038);
+  script_xref(name:"CB-A", value:"08-0109");
+  script_name(english:"Mozilla Seamonkey Multiple Vulnerability July-08 
(Linux)");
+  desc["english"] = "
+
+  Overview : The host is installed with Mozilla Seamonkey, that is prone
+  to multiple vulnerabilities.
+
+  Vulnerability Insight:
+  Issues are due to,
+  - multiple errors in the layout and JavaScript engines that can corrupt
+    memory.
+  - error while handling unprivileged XUL documents that can be exploited
+    to load chrome scripts from a fastload file via <script> elements.
+  - error in mozIJSSubScriptLoader.LoadScript function can bypass
+    XPCNativeWrappers.
+  - error in block re-flow process, which can potentially lead to crash.
+  - error in processing file URLs contained within local directory listings.
+  - errors in the implementation of the Javascript same origin policy
+  - errors in the verification of signed JAR files.
+  - improper implementation of file upload forms result in uploading specially
+    crafted DOM Range and originalTarget elements.
+  - error in Java LiveConnect implementation.
+  - error in processing of Alt Names provided by peer.
+  - error in processing of windows URL shortcuts.
+
+  Impact:
+  Successful exploitation could result in remote arbitrary code execution,
+  spoofing attacks, sensitive information disclosure, and JavaScript code
+  can execute with the privileges of JAR's signer.
+
+  Impact Level: System
+
+  Affected Software/OS:
+  Seamonkey version prior to 1.1.10 on Linux.
+
+  Fix: Upgrade to Seamonkey version 1.1.10 or later
+  http://www.seamonkey-project.org/releases/
+
+  References:
+  http://www.mozilla.org/security/announce/2008/mfsa2008-21.html
+  http://www.mozilla.org/security/announce/2008/mfsa2008-22.html
+  http://www.mozilla.org/security/announce/2008/mfsa2008-23.html
+  http://www.mozilla.org/security/announce/2008/mfsa2008-24.html
+  http://www.mozilla.org/security/announce/2008/mfsa2008-25.html
+  http://www.mozilla.org/security/announce/2008/mfsa2008-27.html
+  http://www.mozilla.org/security/announce/2008/mfsa2008-28.html
+  http://www.mozilla.org/security/announce/2008/mfsa2008-29.html
+  http://www.mozilla.org/security/announce/2008/mfsa2008-30.html
+  http://www.mozilla.org/security/announce/2008/mfsa2008-31.html
+  http://www.mozilla.org/security/announce/2008/mfsa2008-32.html
+  http://www.mozilla.org/security/announce/2008/mfsa2008-33.html
+
+  CVSS Score:
+    CVSS Base Score     : 9.3 (AV:N/AC:M/Au:NR/C:C/I:C/A:C)
+    CVSS Temporal Score : 6.9
+  Risk factor : High";
+
+  script_description(english:desc["english"]);
+  script_summary(english:"Check for the version of Seamonkey");
+  script_category(ACT_GATHER_INFO);
+  script_copyright(english:"Copyright (C) 2008 Intevation GmbH");
+  script_family(english:"Misc.");
+  script_dependencies("gb_seamonkey_detect_lin.nasl");
+  exit(0);
+}
+
+
+# Grep for seamonkey version < 1.1.10
+if(egrep(pattern:"^(0\..*|1\.0(\..*)?|1\.1(\.0?[0-9])?)$",
+         string:get_kb_item("Seamonkey/Linux/Ver"))){
+  security_hole(0);
+}


Property changes on: 
trunk/openvas-plugins/scripts/gb_seamonkey_mult_vuln_july08_lin.nasl
___________________________________________________________________
Name: svn:executable
   + *

Added: trunk/openvas-plugins/scripts/gb_thunderbird_detect_lin.nasl
===================================================================
--- trunk/openvas-plugins/scripts/gb_thunderbird_detect_lin.nasl        
2008-10-06 13:28:08 UTC (rev 1488)
+++ trunk/openvas-plugins/scripts/gb_thunderbird_detect_lin.nasl        
2008-10-07 12:21:23 UTC (rev 1489)
@@ -0,0 +1,88 @@
+###############################################################################
+# OpenVAS Vulnerability Test
+# $Id: gb_thunderbird_detect_lin.nasl 302 2008-10-06 18:10:37Z oct $
+#
+# Mozilla Thunderbird Version Detection (Linux)
+#
+# Authors:
+# Chandan S <[EMAIL PROTECTED]>
+#
+# Copyright:
+# Copyright (c) 2008 Intevation GmbH, http://www.intevation.net
+#
+# This program is free software; you can redistribute it and/or modify
+# it under the terms of the GNU General Public License version 2
+# (or any later version), as published by the Free Software Foundation.
+#
+# This program is distributed in the hope that it will be useful,
+# but WITHOUT ANY WARRANTY; without even the implied warranty of
+# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
+# GNU General Public License for more details.
+#
+# You should have received a copy of the GNU General Public License
+# along with this program; if not, write to the Free Software
+# Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
+###############################################################################
+
+
+if(description)
+{
+  script_id(800018);
+  script_version("Revision: 1.1 ");
+  script_name(english:"Mozilla Thunderbird Version Detection (Linux)");
+  desc["english"] = "
+  Overview : This script retrieves Mozilla ThunderBird Version and
+  saves it in KB.
+
+  Risk factor : Informational";
+
+  script_description(english:desc["english"]);
+  script_family(english:"General");
+  script_category(ACT_GATHER_INFO);
+  script_copyright(english:"Copyright (C) 2008 Intevation GmbH");
+  script_summary(english:"Set Version of Mozilla Thunderbird in KB");
+  exit(0);
+}
+
+
+include("ssh_func.inc");
+
+sock = ssh_login_or_reuse_connection();
+if(!sock){
+  exit(0);
+}
+
+birdName = ssh_cmd(socket:sock, cmd:"thunderbird -v", timeout:120);
+if(birdName =~ "thunderbird.* not found")
+{
+  birdName = ssh_cmd(socket:sock, cmd:"locate -ir thunderbird$", timeout:120);
+  if("thunderbird" >< birdName)
+  {
+    birdName = split(birdName);
+    for(i = 0; i < max_index(birdName); i++)
+      path = path + chomp(birdName[i]) + " -v;";
+
+    birdName = ssh_cmd(socket:sock, cmd:path, timeout:120);
+  }
+  else
+  {
+    # Search for Thunderbird thoroughly (slow).
+    if("yes" >< get_kb_item("global_settings/thorough_tests"))
+    {
+      command = "find / -mount -maxdepth 5 -mindepth 1 -type f -name " +
+                "'thunderbird' -exec '{}' '-v' ';'";
+      birdName = ssh_cmd(socket:sock, cmd:command, timeout:500);
+    }
+  }
+}
+
+# Thunderbird is branded as Icedove in Debian
+if(birdName =~ "Thunderbird|Icedove")
+{
+  birdName = egrep(pattern:"Thunderbird.*Copyright.*mozilla\.org", 
string:birdName);
+  birdName = chomp(birdName);
+  birdVer = eregmatch(pattern:"[.0-9]+", string:birdName);
+  set_kb_item(name:"Thunderbird/Linux/Ver", value:birdVer[0]);
+}
+
+ssh_close_connection();


Property changes on: 
trunk/openvas-plugins/scripts/gb_thunderbird_detect_lin.nasl
___________________________________________________________________
Name: svn:executable
   + *

Added: trunk/openvas-plugins/scripts/gb_thunderbird_mult_vuln_july08_lin.nasl
===================================================================
--- trunk/openvas-plugins/scripts/gb_thunderbird_mult_vuln_july08_lin.nasl      
2008-10-06 13:28:08 UTC (rev 1488)
+++ trunk/openvas-plugins/scripts/gb_thunderbird_mult_vuln_july08_lin.nasl      
2008-10-07 12:21:23 UTC (rev 1489)
@@ -0,0 +1,92 @@
+###############################################################################
+# OpenVAS Vulnerability Test
+# $Id: gb_thunderbird_mult_vuln_july08_lin.nasl 302 2008-10-03 21:00:50Z oct $
+#
+# Mozilla Thunderbird Multiple Vulnerability July-08 (Linux)
+#
+# Authors:
+# Chandan S <[EMAIL PROTECTED]>
+#
+# Copyright:
+# Copyright (c) 2008 Intevation GmbH, http://www.intevation.net
+#
+# This program is free software; you can redistribute it and/or modify
+# it under the terms of the GNU General Public License version 2
+# (or any later version), as published by the Free Software Foundation.
+#
+# This program is distributed in the hope that it will be useful,
+# but WITHOUT ANY WARRANTY; without even the implied warranty of
+# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
+# GNU General Public License for more details.
+#
+# You should have received a copy of the GNU General Public License
+# along with this program; if not, write to the Free Software
+# Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
+###############################################################################
+
+if(description)
+{
+  script_id(800021);
+  script_version("$Revision: 1.1 $");
+  script_cve_id("CVE-2008-2798", "CVE-2008-2799", "CVE-2008-2802", 
"CVE-2008-2803",
+                "CVE-2008-2807", "CVE-2008-2809", "CVE-2008-2811");
+  script_bugtraq_id(30038);
+  script_xref(name:"CB-A", value:"08-0109");
+  script_name(english:"Mozilla Thunderbird Multiple Vulnerability July-08 
(Linux)");
+  desc["english"] = "
+
+  Overview : The host is installed with Mozilla Thunderbird, that is prone
+  to multiple vulnerabilities.
+
+  Vulnerability Insight:
+  The issues are due to,
+  - multiple errors in the layout and JavaScript engines that can corrupt
+    memory.
+  - error while handling unprivileged XUL documents that can be exploited
+    to load chrome scripts from a fastload file via <script> elements.
+  - error in mozIJSSubScriptLoader.LoadScript function that can bypass
+    XPCNativeWrappers.
+  - error in block re-flow process, which can potentially lead to crash.
+  - errors in the implementation of the Javascript same origin policy
+  - error in processing of Alt Names provided by peer.
+  - error in processing of windows URL shortcuts.
+
+  Impact: Successful exploitation could result in remote arbitrary code 
execution,
+  spoofing attacks, sensitive information disclosure, and can crash the 
browser.
+
+  Impact Level: System
+
+  Affected Software/OS:
+  Thunderbird version prior to 2.0.0.16 on Linux.
+
+  Fix: Upgrade to Thunderbird version 2.0.0.16
+  http://www.mozilla.com/en-US/thunderbird/all-older.html
+
+  References :
+  http://www.mozilla.org/security/announce/2008/mfsa2008-21.html
+  http://www.mozilla.org/security/announce/2008/mfsa2008-24.html
+  http://www.mozilla.org/security/announce/2008/mfsa2008-25.html
+  http://www.mozilla.org/security/announce/2008/mfsa2008-29.html
+  http://www.mozilla.org/security/announce/2008/mfsa2008-31.html
+  http://www.mozilla.org/security/announce/2008/mfsa2008-33.html
+
+  CVSS Score:
+    CVSS Base Score     : 9.3 (AV:N/AC:M/Au:NR/C:C/I:C/A:C)
+    CVSS Temporal Score : 6.9
+  Risk factor : High";
+
+  script_description(english:desc["english"]);
+  script_summary(english:"Check for the version of Thunderbird");
+  script_category(ACT_GATHER_INFO);
+  script_copyright(english:"Copyright (C) 2008 Intevation GmbH");
+  script_family(english:"Misc.");
+  script_dependencies("gb_thunderbird_detect_lin.nasl");
+  exit(0);
+}
+
+
+# Grep for thunderbird version < 2.0.0.16
+if(egrep(pattern:"^([01]\..*|2\.0(\.0\.(0?[0-9]|1[0-5]))?)$",
+         string:get_kb_item("Thunderbird/Linux/Ver"))){
+  security_hole(0);
+}


Property changes on: 
trunk/openvas-plugins/scripts/gb_thunderbird_mult_vuln_july08_lin.nasl
___________________________________________________________________
Name: svn:executable
   + *

_______________________________________________
Openvas-commits mailing list
[email protected]
http://lists.wald.intevation.org/mailman/listinfo/openvas-commits

Reply via email to