Your Company Fixed Vulnerability Descriptions - April 2011

Reference:
YC 201135
Sub-Report:
Other
AllNewFixed [Selected] Stoplist

Show Category: 
Filter by CVE or Vulnerability Id:      

Expand / collapse allCollapse Details   Collapse Systems

Collapse   Vulnerability 10021Identd enabledCollapse  1 SystemLow Risk
DescriptionThe ident service appears to be running on the remote host. This service provides sensitive information to an attacker, allowing them to enumerate which accounts are running which services. 
SolutionDisable this service or restrict it to trusted IP addresses 
CVE Reference CVE-1999-0629CVSS2 .0 (Low) (AV:N/AC:L/Au:N/C:N/I:N/A:N)
Systemswww.your_company.fr (192.168.0.105)    

Collapse   Vulnerability 10640Kerberos PingPong DOSCollapse  1 SystemLow Risk
DescriptionThe remote kerberos server seems to be vulnerable to a pingpong attack. When contacted on the UDP port, this service always responds, even to bogus data. An attacker can cause a denial of service attack, by spoofing a packet between two machines running this service. This will cause them to spew data at each other, saturating the network.  
SolutionDisable this service in /etc/inetd.conf.  
CVE Reference CVE-1999-0103CVSS2 5.0 (Medium) (AV:N/AC:L/Au:N/C:N/I:N/A:P)
Systemswww.your_company.fr (192.168.0.105)    

Scans by Westpoint Ltd