Author: chandra
Date: 2008-10-07 14:21:23 +0200 (Tue, 07 Oct 2008)
New Revision: 1489
Added:
trunk/openvas-plugins/scripts/gb_firefox_detect_lin.nasl
trunk/openvas-plugins/scripts/gb_firefox_mult_vuln_july08_lin.nasl
trunk/openvas-plugins/scripts/gb_seamonkey_detect_lin.nasl
trunk/openvas-plugins/scripts/gb_seamonkey_mult_vuln_july08_lin.nasl
trunk/openvas-plugins/scripts/gb_thunderbird_detect_lin.nasl
trunk/openvas-plugins/scripts/gb_thunderbird_mult_vuln_july08_lin.nasl
Modified:
trunk/openvas-plugins/ChangeLog
Log:
Added new plugins
Modified: trunk/openvas-plugins/ChangeLog
===================================================================
--- trunk/openvas-plugins/ChangeLog 2008-10-06 13:28:08 UTC (rev 1488)
+++ trunk/openvas-plugins/ChangeLog 2008-10-07 12:21:23 UTC (rev 1489)
@@ -1,3 +1,12 @@
+2008-10-07 Chandrashekhar B <[EMAIL PROTECTED]>
+ * scripts/gb_thunderbird_mult_vuln_july08_lin.nasl,
+ scripts/gb_seamonkey_mult_vuln_july08_lin.nasl,
+ scripts/gb_firefox_detect_lin.nasl,
+ scripts/gb_thunderbird_detect_lin.nasl,
+ scripts/gb_firefox_mult_vuln_july08_lin.nasl,
+ scripts/gb_seamonkey_detect_lin.nasl:
+ Added new plugins
+
2008-10-06 Chandrashekhar B <[EMAIL PROTECTED]>
* scripts/gb_thunderbird_detect_win.nasl,
scripts/gb_thunderbird_mult_vuln_july08_win.nasl,
Added: trunk/openvas-plugins/scripts/gb_firefox_detect_lin.nasl
===================================================================
--- trunk/openvas-plugins/scripts/gb_firefox_detect_lin.nasl 2008-10-06
13:28:08 UTC (rev 1488)
+++ trunk/openvas-plugins/scripts/gb_firefox_detect_lin.nasl 2008-10-07
12:21:23 UTC (rev 1489)
@@ -0,0 +1,88 @@
+###############################################################################
+# OpenVAS Vulnerability Test
+# $Id: gb_firefox_detect_lin.nasl 302 2008-10-06 15:57:11Z oct $
+#
+# Mozilla Firefox Version Detection (Linux)
+#
+# Authors:
+# Chandan S <[EMAIL PROTECTED]>
+#
+# Copyright:
+# Copyright (c) 2008 Intevation GmbH, http://www.intevation.net
+#
+# This program is free software; you can redistribute it and/or modify
+# it under the terms of the GNU General Public License version 2
+# (or any later version), as published by the Free Software Foundation.
+#
+# This program is distributed in the hope that it will be useful,
+# but WITHOUT ANY WARRANTY; without even the implied warranty of
+# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
+# GNU General Public License for more details.
+#
+# You should have received a copy of the GNU General Public License
+# along with this program; if not, write to the Free Software
+# Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
+###############################################################################
+
+
+if(description)
+{
+ script_id(800017);
+ script_version("Revision: 1.1 ");
+ script_name(english:"Mozilla Firefox Version Detection (Linux)");
+ desc["english"] = "
+ Overview : This script finds the Mozilla Firefox installed version on Linux
+ and save the version in KB.
+
+ Risk factor : Informational";
+
+ script_description(english:desc["english"]);
+ script_family(english:"General");
+ script_category(ACT_GATHER_INFO);
+ script_copyright(english:"Copyright (C) 2008 Intevation GmbH");
+ script_summary(english:"Set File Version of Mozilla Firefox in KB");
+ exit(0);
+}
+
+
+include("ssh_func.inc");
+
+sock = ssh_login_or_reuse_connection();
+if(!sock){
+ exit(0);
+}
+
+foxName = ssh_cmd(socket:sock, cmd:"firefox -v", timeout:120);
+if(foxName =~ "firefox.* not found")
+{
+ foxName = ssh_cmd(socket:sock, cmd:"locate -ir firefox$", timeout:120);
+ if("firefox" >< foxName)
+ {
+ foxName = split(foxName);
+ for(i = 0; i < max_index(foxName); i++)
+ path = path + chomp(foxName[i]) + " -v;";
+
+ foxName = ssh_cmd(socket:sock, cmd:path, timeout:120);
+ }
+ else
+ {
+ # Search for Firefox thoroughly (slow).
+ if("yes" >< get_kb_item("global_settings/thorough_tests"))
+ {
+ command = "find / -mount -maxdepth 5 -mindepth 1 -type f -name " +
+ "'firefox' -exec '{}' '-v' ';'";
+ foxName = ssh_cmd(socket:sock, cmd:command, timeout:500);
+ }
+ }
+}
+
+# Firefox is branded as Iceweasel in Debian
+if(foxName =~ "Firefox|Iceweasel")
+{
+ foxName = egrep(pattern:"Mozilla.*Copyright.*mozilla\.org", string:foxName);
+ foxName = chomp(foxName);
+ foxVer = eregmatch(pattern:"[.0-9]+", string:foxName);
+ set_kb_item(name:"Firefox/Linux/Ver", value:foxVer[0]);
+}
+
+ssh_close_connection();
Added: trunk/openvas-plugins/scripts/gb_firefox_mult_vuln_july08_lin.nasl
===================================================================
--- trunk/openvas-plugins/scripts/gb_firefox_mult_vuln_july08_lin.nasl
2008-10-06 13:28:08 UTC (rev 1488)
+++ trunk/openvas-plugins/scripts/gb_firefox_mult_vuln_july08_lin.nasl
2008-10-07 12:21:23 UTC (rev 1489)
@@ -0,0 +1,107 @@
+###############################################################################
+# OpenVAS Vulnerability Test
+# $Id: gb_firefox_mult_vuln_july08_lin.nasl 302 2008-10-03 20:58:15Z oct $
+#
+# Mozilla Firefox Multiple Vulnerability July-08 (Linux)
+#
+# Authors:
+# Chandan S <[EMAIL PROTECTED]>
+#
+# Copyright:
+# Copyright (c) 2008 Intevation GmbH, http://www.intevation.net
+#
+# This program is free software; you can redistribute it and/or modify
+# it under the terms of the GNU General Public License version 2
+# (or any later version), as published by the Free Software Foundation.
+#
+# This program is distributed in the hope that it will be useful,
+# but WITHOUT ANY WARRANTY; without even the implied warranty of
+# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
+# GNU General Public License for more details.
+#
+# You should have received a copy of the GNU General Public License
+# along with this program; if not, write to the Free Software
+# Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
+###############################################################################
+
+if(description)
+{
+ script_id(800020);
+ script_version("$Revision: 1.1 $");
+ script_cve_id("CVE-2008-2798", "CVE-2008-2799", "CVE-2008-2800",
"CVE-2008-2801",
+ "CVE-2008-2802", "CVE-2008-2803", "CVE-2008-2805",
"CVE-2008-2806",
+ "CVE-2008-2807", "CVE-2008-2808", "CVE-2008-2809",
"CVE-2008-2810",
+ "CVE-2008-2811");
+ script_bugtraq_id(30038);
+ script_xref(name:"CB-A", value:"08-0109");
+ script_name(english:"Mozilla Firefox Multiple Vulnerability July-08
(Linux)");
+ desc["english"] = "
+
+ Overview: The host is installed with Mozilla Firefox browser, that is prone
+ to multiple vulnerabilities.
+
+ Vulnerability Insight:
+ Issues in browser are due to,
+ - multiple errors in the layout and JavaScript engines that can corrupt
+ memory.
+ - error while handling unprivileged XUL documents that can be exploited to
+ load chrome scripts from a fastload file via <script> elements.
+ - error in mozIJSSubScriptLoader.LoadScript function can bypass
+ XPCNativeWrappers.
+ - error in block re-flow process, which can potentially lead to crash.
+ - error in processing file URLs contained within local directory listings.
+ - errors in the implementation of the Javascript same origin policy
+ - errors in the verification of signed JAR files.
+ - improper implementation of file upload forms result in uploading specially
+ crafted DOM Range and originalTarget elements.
+ - error in Java LiveConnect implementation.
+ - error in processing of Alt Names provided by peer.
+ - error in processing of windows URL shortcuts.
+
+ Impact:
+ Successful exploitation could result in remote arbitrary code execution,
+ spoofing attacks, sensitive information disclosure, and JavaScript code can
+ be executed with the privileges of JAR's signer.
+
+ Impact Level: System
+
+ Affected Software/OS:
+ Firefox version prior to 2.0.0.15 on Linux.
+
+ Fix: Upgrade to Firefox version 2.0.0.15
+ http://www.mozilla.com/en-US/firefox/all-older.html
+
+ References :
+ http://www.mozilla.org/security/announce/2008/mfsa2008-21.html
+ http://www.mozilla.org/security/announce/2008/mfsa2008-22.html
+ http://www.mozilla.org/security/announce/2008/mfsa2008-23.html
+ http://www.mozilla.org/security/announce/2008/mfsa2008-24.html
+ http://www.mozilla.org/security/announce/2008/mfsa2008-25.html
+ http://www.mozilla.org/security/announce/2008/mfsa2008-27.html
+ http://www.mozilla.org/security/announce/2008/mfsa2008-28.html
+ http://www.mozilla.org/security/announce/2008/mfsa2008-29.html
+ http://www.mozilla.org/security/announce/2008/mfsa2008-30.html
+ http://www.mozilla.org/security/announce/2008/mfsa2008-31.html
+ http://www.mozilla.org/security/announce/2008/mfsa2008-32.html
+ http://www.mozilla.org/security/announce/2008/mfsa2008-33.html
+
+ CVSS Score:
+ CVSS Base Score : 9.3 (AV:N/AC:M/Au:NR/C:C/I:C/A:C)
+ CVSS Temporal Score : 6.9
+ Risk factor : High";
+
+ script_description(english:desc["english"]);
+ script_summary(english:"Check for the version of Firefox");
+ script_category(ACT_GATHER_INFO);
+ script_copyright(english:"Copyright (C) 2008 Intevation GmbH");
+ script_family(english:"Misc.");
+ script_dependencies("gb_firefox_detect_lin.nasl");
+ exit(0);
+}
+
+
+# Grep for firefox version < 2.0.0.15
+if(egrep(pattern:"^([01]\..*|2\.0(\.0\.(0?[0-9]|1[0-4]))?)$",
+ string:get_kb_item("Firefox/Linux/Ver"))){
+ security_hole(0);
+}
Property changes on:
trunk/openvas-plugins/scripts/gb_firefox_mult_vuln_july08_lin.nasl
___________________________________________________________________
Name: svn:executable
+ *
Added: trunk/openvas-plugins/scripts/gb_seamonkey_detect_lin.nasl
===================================================================
--- trunk/openvas-plugins/scripts/gb_seamonkey_detect_lin.nasl 2008-10-06
13:28:08 UTC (rev 1488)
+++ trunk/openvas-plugins/scripts/gb_seamonkey_detect_lin.nasl 2008-10-07
12:21:23 UTC (rev 1489)
@@ -0,0 +1,92 @@
+###############################################################################
+# OpenVAS Vulnerability Test
+# $Id: gb_seamonkey_detect_lin.nasl 302 2008-10-06 18:59:15Z oct $
+#
+# Mozilla Seamonkey Version Detection (Linux)
+#
+# Authors:
+# Chandan S <[EMAIL PROTECTED]>
+#
+# Copyright:
+# Copyright (c) 2008 Intevation GmbH, http://www.intevation.net
+#
+# This program is free software; you can redistribute it and/or modify
+# it under the terms of the GNU General Public License version 2
+# (or any later version), as published by the Free Software Foundation.
+#
+# This program is distributed in the hope that it will be useful,
+# but WITHOUT ANY WARRANTY; without even the implied warranty of
+# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
+# GNU General Public License for more details.
+#
+# You should have received a copy of the GNU General Public License
+# along with this program; if not, write to the Free Software
+# Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
+###############################################################################
+
+
+if(description)
+{
+ script_id(800019);
+ script_version("Revision: 1.1 ");
+ script_name(english:"Mozilla SeaMonkey Version Detection (Linux)");
+ desc["english"] = "
+ Overview : This script finds the Mozilla SeaMonkey installed version on
+ Linux and saves the version in KB.
+
+ Risk factor : Informational";
+
+ script_description(english:desc["english"]);
+ script_family(english:"General");
+ script_category(ACT_GATHER_INFO);
+ script_copyright(english:"Copyright (C) 2008 Intevation GmbH");
+ script_summary(english:"Set File Version of Mozilla SeaMonkey in KB");
+ exit(0);
+}
+
+
+include("ssh_func.inc");
+
+sock = ssh_login_or_reuse_connection();
+if(!sock){
+ exit(0);
+}
+
+seaName = ssh_cmd(socket:sock, cmd:"seamonkey -v", timeout:120);
+if(seaName =~ "seamonkey.* not found"){
+ seaName = ssh_cmd(socket:sock, cmd:"iceape -v", timeout:120);
+}
+
+if(seaName =~ "iceape.* not found")
+{
+ seaName = ssh_cmd(socket:sock, cmd:"locate -ir seamonkey$", timeout:120);
+ if("seamonkey" >< seaName)
+ {
+ seaName = split(seaName);
+ for(i = 0; i < max_index(seaName); i++)
+ path = path + chomp(seaName[i]) + " -v;";
+
+ seaName = ssh_cmd(socket:sock, cmd:path, timeout:120);
+ }
+ else
+ {
+ # Check for Seamonkey thoroughly (slow).
+ if("yes" >< get_kb_item("global_settings/thorough_tests"))
+ {
+ command = "find / -mount -maxdepth 5 -mindepth 1 -type f -name " +
+ "'seamonkey' -exec '{}' '-v' ';'";
+ seaName = ssh_cmd(socket:sock, cmd:command, timeout:500);
+ }
+ }
+}
+
+# Seamonkey is branded as Iceape in Debian
+if(seaName =~ "Seamonkey|Iceape")
+{
+ seaName = egrep(pattern:"(SeaMonkey|Iceape).*Copyright.*mozilla\.org",
string:seaName);
+ seaName = chomp(seaName);
+ seaVer = eregmatch(pattern:"[.0-9]+", string:seaName);
+ set_kb_item(name:"Seamonkey/Linux/Ver", value:seaVer[0]);
+}
+
+ssh_close_connection();
Added: trunk/openvas-plugins/scripts/gb_seamonkey_mult_vuln_july08_lin.nasl
===================================================================
--- trunk/openvas-plugins/scripts/gb_seamonkey_mult_vuln_july08_lin.nasl
2008-10-06 13:28:08 UTC (rev 1488)
+++ trunk/openvas-plugins/scripts/gb_seamonkey_mult_vuln_july08_lin.nasl
2008-10-07 12:21:23 UTC (rev 1489)
@@ -0,0 +1,107 @@
+###############################################################################
+# OpenVAS Vulnerability Test
+# $Id: gb_seamonkey_mult_vuln_july08_lin.nasl 302 2008-10-03 21:03:20Z oct $
+#
+# Mozilla Seamonkey Multiple Vulnerability July-08 (Linux)
+#
+# Authors:
+# Chandan S <[EMAIL PROTECTED]>
+#
+# Copyright:
+# Copyright (c) 2008 Intevation GmbH, http://www.intevation.net
+#
+# This program is free software; you can redistribute it and/or modify
+# it under the terms of the GNU General Public License version 2
+# (or any later version), as published by the Free Software Foundation.
+#
+# This program is distributed in the hope that it will be useful,
+# but WITHOUT ANY WARRANTY; without even the implied warranty of
+# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
+# GNU General Public License for more details.
+#
+# You should have received a copy of the GNU General Public License
+# along with this program; if not, write to the Free Software
+# Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
+###############################################################################
+
+if(description)
+{
+ script_id(800022);
+ script_version("$Revision: 1.1 $");
+ script_cve_id("CVE-2008-2798", "CVE-2008-2799", "CVE-2008-2800",
"CVE-2008-2801",
+ "CVE-2008-2802", "CVE-2008-2803", "CVE-2008-2805",
"CVE-2008-2806",
+ "CVE-2008-2807", "CVE-2008-2808", "CVE-2008-2809",
"CVE-2008-2810",
+ "CVE-2008-2811");
+ script_bugtraq_id(30038);
+ script_xref(name:"CB-A", value:"08-0109");
+ script_name(english:"Mozilla Seamonkey Multiple Vulnerability July-08
(Linux)");
+ desc["english"] = "
+
+ Overview : The host is installed with Mozilla Seamonkey, that is prone
+ to multiple vulnerabilities.
+
+ Vulnerability Insight:
+ Issues are due to,
+ - multiple errors in the layout and JavaScript engines that can corrupt
+ memory.
+ - error while handling unprivileged XUL documents that can be exploited
+ to load chrome scripts from a fastload file via <script> elements.
+ - error in mozIJSSubScriptLoader.LoadScript function can bypass
+ XPCNativeWrappers.
+ - error in block re-flow process, which can potentially lead to crash.
+ - error in processing file URLs contained within local directory listings.
+ - errors in the implementation of the Javascript same origin policy
+ - errors in the verification of signed JAR files.
+ - improper implementation of file upload forms result in uploading specially
+ crafted DOM Range and originalTarget elements.
+ - error in Java LiveConnect implementation.
+ - error in processing of Alt Names provided by peer.
+ - error in processing of windows URL shortcuts.
+
+ Impact:
+ Successful exploitation could result in remote arbitrary code execution,
+ spoofing attacks, sensitive information disclosure, and JavaScript code
+ can execute with the privileges of JAR's signer.
+
+ Impact Level: System
+
+ Affected Software/OS:
+ Seamonkey version prior to 1.1.10 on Linux.
+
+ Fix: Upgrade to Seamonkey version 1.1.10 or later
+ http://www.seamonkey-project.org/releases/
+
+ References:
+ http://www.mozilla.org/security/announce/2008/mfsa2008-21.html
+ http://www.mozilla.org/security/announce/2008/mfsa2008-22.html
+ http://www.mozilla.org/security/announce/2008/mfsa2008-23.html
+ http://www.mozilla.org/security/announce/2008/mfsa2008-24.html
+ http://www.mozilla.org/security/announce/2008/mfsa2008-25.html
+ http://www.mozilla.org/security/announce/2008/mfsa2008-27.html
+ http://www.mozilla.org/security/announce/2008/mfsa2008-28.html
+ http://www.mozilla.org/security/announce/2008/mfsa2008-29.html
+ http://www.mozilla.org/security/announce/2008/mfsa2008-30.html
+ http://www.mozilla.org/security/announce/2008/mfsa2008-31.html
+ http://www.mozilla.org/security/announce/2008/mfsa2008-32.html
+ http://www.mozilla.org/security/announce/2008/mfsa2008-33.html
+
+ CVSS Score:
+ CVSS Base Score : 9.3 (AV:N/AC:M/Au:NR/C:C/I:C/A:C)
+ CVSS Temporal Score : 6.9
+ Risk factor : High";
+
+ script_description(english:desc["english"]);
+ script_summary(english:"Check for the version of Seamonkey");
+ script_category(ACT_GATHER_INFO);
+ script_copyright(english:"Copyright (C) 2008 Intevation GmbH");
+ script_family(english:"Misc.");
+ script_dependencies("gb_seamonkey_detect_lin.nasl");
+ exit(0);
+}
+
+
+# Grep for seamonkey version < 1.1.10
+if(egrep(pattern:"^(0\..*|1\.0(\..*)?|1\.1(\.0?[0-9])?)$",
+ string:get_kb_item("Seamonkey/Linux/Ver"))){
+ security_hole(0);
+}
Property changes on:
trunk/openvas-plugins/scripts/gb_seamonkey_mult_vuln_july08_lin.nasl
___________________________________________________________________
Name: svn:executable
+ *
Added: trunk/openvas-plugins/scripts/gb_thunderbird_detect_lin.nasl
===================================================================
--- trunk/openvas-plugins/scripts/gb_thunderbird_detect_lin.nasl
2008-10-06 13:28:08 UTC (rev 1488)
+++ trunk/openvas-plugins/scripts/gb_thunderbird_detect_lin.nasl
2008-10-07 12:21:23 UTC (rev 1489)
@@ -0,0 +1,88 @@
+###############################################################################
+# OpenVAS Vulnerability Test
+# $Id: gb_thunderbird_detect_lin.nasl 302 2008-10-06 18:10:37Z oct $
+#
+# Mozilla Thunderbird Version Detection (Linux)
+#
+# Authors:
+# Chandan S <[EMAIL PROTECTED]>
+#
+# Copyright:
+# Copyright (c) 2008 Intevation GmbH, http://www.intevation.net
+#
+# This program is free software; you can redistribute it and/or modify
+# it under the terms of the GNU General Public License version 2
+# (or any later version), as published by the Free Software Foundation.
+#
+# This program is distributed in the hope that it will be useful,
+# but WITHOUT ANY WARRANTY; without even the implied warranty of
+# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
+# GNU General Public License for more details.
+#
+# You should have received a copy of the GNU General Public License
+# along with this program; if not, write to the Free Software
+# Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
+###############################################################################
+
+
+if(description)
+{
+ script_id(800018);
+ script_version("Revision: 1.1 ");
+ script_name(english:"Mozilla Thunderbird Version Detection (Linux)");
+ desc["english"] = "
+ Overview : This script retrieves Mozilla ThunderBird Version and
+ saves it in KB.
+
+ Risk factor : Informational";
+
+ script_description(english:desc["english"]);
+ script_family(english:"General");
+ script_category(ACT_GATHER_INFO);
+ script_copyright(english:"Copyright (C) 2008 Intevation GmbH");
+ script_summary(english:"Set Version of Mozilla Thunderbird in KB");
+ exit(0);
+}
+
+
+include("ssh_func.inc");
+
+sock = ssh_login_or_reuse_connection();
+if(!sock){
+ exit(0);
+}
+
+birdName = ssh_cmd(socket:sock, cmd:"thunderbird -v", timeout:120);
+if(birdName =~ "thunderbird.* not found")
+{
+ birdName = ssh_cmd(socket:sock, cmd:"locate -ir thunderbird$", timeout:120);
+ if("thunderbird" >< birdName)
+ {
+ birdName = split(birdName);
+ for(i = 0; i < max_index(birdName); i++)
+ path = path + chomp(birdName[i]) + " -v;";
+
+ birdName = ssh_cmd(socket:sock, cmd:path, timeout:120);
+ }
+ else
+ {
+ # Search for Thunderbird thoroughly (slow).
+ if("yes" >< get_kb_item("global_settings/thorough_tests"))
+ {
+ command = "find / -mount -maxdepth 5 -mindepth 1 -type f -name " +
+ "'thunderbird' -exec '{}' '-v' ';'";
+ birdName = ssh_cmd(socket:sock, cmd:command, timeout:500);
+ }
+ }
+}
+
+# Thunderbird is branded as Icedove in Debian
+if(birdName =~ "Thunderbird|Icedove")
+{
+ birdName = egrep(pattern:"Thunderbird.*Copyright.*mozilla\.org",
string:birdName);
+ birdName = chomp(birdName);
+ birdVer = eregmatch(pattern:"[.0-9]+", string:birdName);
+ set_kb_item(name:"Thunderbird/Linux/Ver", value:birdVer[0]);
+}
+
+ssh_close_connection();
Property changes on:
trunk/openvas-plugins/scripts/gb_thunderbird_detect_lin.nasl
___________________________________________________________________
Name: svn:executable
+ *
Added: trunk/openvas-plugins/scripts/gb_thunderbird_mult_vuln_july08_lin.nasl
===================================================================
--- trunk/openvas-plugins/scripts/gb_thunderbird_mult_vuln_july08_lin.nasl
2008-10-06 13:28:08 UTC (rev 1488)
+++ trunk/openvas-plugins/scripts/gb_thunderbird_mult_vuln_july08_lin.nasl
2008-10-07 12:21:23 UTC (rev 1489)
@@ -0,0 +1,92 @@
+###############################################################################
+# OpenVAS Vulnerability Test
+# $Id: gb_thunderbird_mult_vuln_july08_lin.nasl 302 2008-10-03 21:00:50Z oct $
+#
+# Mozilla Thunderbird Multiple Vulnerability July-08 (Linux)
+#
+# Authors:
+# Chandan S <[EMAIL PROTECTED]>
+#
+# Copyright:
+# Copyright (c) 2008 Intevation GmbH, http://www.intevation.net
+#
+# This program is free software; you can redistribute it and/or modify
+# it under the terms of the GNU General Public License version 2
+# (or any later version), as published by the Free Software Foundation.
+#
+# This program is distributed in the hope that it will be useful,
+# but WITHOUT ANY WARRANTY; without even the implied warranty of
+# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
+# GNU General Public License for more details.
+#
+# You should have received a copy of the GNU General Public License
+# along with this program; if not, write to the Free Software
+# Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
+###############################################################################
+
+if(description)
+{
+ script_id(800021);
+ script_version("$Revision: 1.1 $");
+ script_cve_id("CVE-2008-2798", "CVE-2008-2799", "CVE-2008-2802",
"CVE-2008-2803",
+ "CVE-2008-2807", "CVE-2008-2809", "CVE-2008-2811");
+ script_bugtraq_id(30038);
+ script_xref(name:"CB-A", value:"08-0109");
+ script_name(english:"Mozilla Thunderbird Multiple Vulnerability July-08
(Linux)");
+ desc["english"] = "
+
+ Overview : The host is installed with Mozilla Thunderbird, that is prone
+ to multiple vulnerabilities.
+
+ Vulnerability Insight:
+ The issues are due to,
+ - multiple errors in the layout and JavaScript engines that can corrupt
+ memory.
+ - error while handling unprivileged XUL documents that can be exploited
+ to load chrome scripts from a fastload file via <script> elements.
+ - error in mozIJSSubScriptLoader.LoadScript function that can bypass
+ XPCNativeWrappers.
+ - error in block re-flow process, which can potentially lead to crash.
+ - errors in the implementation of the Javascript same origin policy
+ - error in processing of Alt Names provided by peer.
+ - error in processing of windows URL shortcuts.
+
+ Impact: Successful exploitation could result in remote arbitrary code
execution,
+ spoofing attacks, sensitive information disclosure, and can crash the
browser.
+
+ Impact Level: System
+
+ Affected Software/OS:
+ Thunderbird version prior to 2.0.0.16 on Linux.
+
+ Fix: Upgrade to Thunderbird version 2.0.0.16
+ http://www.mozilla.com/en-US/thunderbird/all-older.html
+
+ References :
+ http://www.mozilla.org/security/announce/2008/mfsa2008-21.html
+ http://www.mozilla.org/security/announce/2008/mfsa2008-24.html
+ http://www.mozilla.org/security/announce/2008/mfsa2008-25.html
+ http://www.mozilla.org/security/announce/2008/mfsa2008-29.html
+ http://www.mozilla.org/security/announce/2008/mfsa2008-31.html
+ http://www.mozilla.org/security/announce/2008/mfsa2008-33.html
+
+ CVSS Score:
+ CVSS Base Score : 9.3 (AV:N/AC:M/Au:NR/C:C/I:C/A:C)
+ CVSS Temporal Score : 6.9
+ Risk factor : High";
+
+ script_description(english:desc["english"]);
+ script_summary(english:"Check for the version of Thunderbird");
+ script_category(ACT_GATHER_INFO);
+ script_copyright(english:"Copyright (C) 2008 Intevation GmbH");
+ script_family(english:"Misc.");
+ script_dependencies("gb_thunderbird_detect_lin.nasl");
+ exit(0);
+}
+
+
+# Grep for thunderbird version < 2.0.0.16
+if(egrep(pattern:"^([01]\..*|2\.0(\.0\.(0?[0-9]|1[0-5]))?)$",
+ string:get_kb_item("Thunderbird/Linux/Ver"))){
+ security_hole(0);
+}
Property changes on:
trunk/openvas-plugins/scripts/gb_thunderbird_mult_vuln_july08_lin.nasl
___________________________________________________________________
Name: svn:executable
+ *
_______________________________________________
Openvas-commits mailing list
[email protected]
http://lists.wald.intevation.org/mailman/listinfo/openvas-commits