<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://forums.eeye.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Vulnerability Assessment</title><link>http://forums.eeye.com/forums/18.aspx</link><description>Post issues related to your Vulnerability Assessment scans in this forum</description><dc:language>en</dc:language><generator>CommunityServer 2007.1 SP1 (Build: 30415.43)</generator><item><title>Office XP False Positives</title><link>http://forums.eeye.com/forums/thread/5027.aspx</link><pubDate>Mon, 26 Oct 2009 01:21:01 GMT</pubDate><guid isPermaLink="false">a21f7e33-d546-44ed-90ca-b1df844505d6:5027</guid><dc:creator>eyesonly</dc:creator><slash:comments>14</slash:comments><comments>http://forums.eeye.com/forums/thread/5027.aspx</comments><wfw:commentRss>http://forums.eeye.com/forums/commentrss.aspx?SectionID=18&amp;PostID=5027</wfw:commentRss><description>&lt;p&gt;I recently installed Windows XP &amp;amp; Office XP on a brand new disk. &amp;nbsp;I installed the service packs in chronological order. &amp;nbsp;Next, I went to Microsoft Update and applied all critical patches. &amp;nbsp;Microsoft Update reported NO critical updates. &amp;nbsp;Windows XP SP3 &amp;amp; Office XP SP3. &lt;/p&gt;
&lt;p&gt;Next, I installed Blink Personal, then updated the software &amp;amp; virus definitions. &amp;nbsp; I ran a Vulnerability Assessment and it reported the following 3 critical updates needed to be applied: &lt;/p&gt;
&lt;p&gt;Microsoft Office One Note URI Remote Code Execution (955047) - Office XP&lt;/p&gt;
&lt;p&gt;Microsoft Office Remote Code Execution (949030) - Office XP&lt;/p&gt;
&lt;p&gt;Microsoft Office Remote Code Execution (934873) - Office XP&lt;/p&gt;
&lt;p&gt;I checked the links to the Microsoft Bulletins to determine whether the updates may have already been applied in some kind of roll-out or cumulative update. &amp;nbsp;Although the Microsoft Bulletines did not mention any roll-out or cumulative updates that superceded the bulletins, I was able to find the files updated in the file information sections. &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;My current systems (Windows XP SP3, Microsoft Office XP SP3) reports: &lt;/p&gt;
&lt;p&gt;mso.dll &amp;nbsp; &amp;nbsp; 10.0.6856.0 &amp;nbsp; &amp;nbsp; 9/04/09 &amp;nbsp; &amp;nbsp; 9811792&lt;/p&gt;
&lt;p&gt;ietag.dll &amp;nbsp; &amp;nbsp; 10.0.6731.0 &amp;nbsp; &amp;nbsp; 9/04/09 &amp;nbsp; &amp;nbsp; 105152&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;According the Microsoft Bulletins: &lt;/p&gt;
&lt;p&gt;Microsoft Office One Note URI Remote Code Execution (955047) - Office XP per http://support.microsoft.com/default.aspx?scid=95507&lt;/p&gt;
&lt;p&gt;mso.dll &amp;nbsp; &amp;nbsp; 10.0.6845.0 &amp;nbsp; &amp;nbsp; 6/11/08 &amp;nbsp; &amp;nbsp; 9819136&lt;/p&gt;
&lt;p&gt;ietag.dll &amp;nbsp; &amp;nbsp; 10.0.6731.0 &amp;nbsp; &amp;nbsp; 6/11/08 &amp;nbsp; &amp;nbsp; &amp;nbsp;105152&lt;/p&gt;
&lt;p&gt;Microsoft Office Remote Code Execution (949030) - Office XP per www.microsoft.com/technet/security/bulletin/ms08-016.mspx&lt;/p&gt;
&lt;p&gt;mso.dll &amp;nbsp; &amp;nbsp; 10.0.6839.0 &amp;nbsp; &amp;nbsp; 10/30/07 &amp;nbsp; &amp;nbsp; 9819136&lt;/p&gt;
&lt;p&gt;ietag.dll &amp;nbsp; &amp;nbsp; 10.0.6731 &amp;nbsp; &amp;nbsp; 9/10/04 &amp;nbsp; &amp;nbsp; 105152&lt;/p&gt;
&lt;p&gt;Microsoft Office Remote Code Execution (934873) - Office XP per www.microsoft.com/technet/security/bulletin/ms07-025.mspx&lt;/p&gt;
&lt;p&gt;mso.dll &amp;nbsp; &amp;nbsp; 10.0.6830.0 &amp;nbsp; &amp;nbsp; 3/26/07 &amp;nbsp; &amp;nbsp; 9819480&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;As you see, I have the most recent versons and most recent dated files even though I did not apply any of the 3 Microsoft Updates. &amp;nbsp;While I don&amp;#39;t know exactly what Micosoft patch(es)/update(s) are responsible, I do know that my system is completely patched and Vulnerability Assessment incorrectly tells me to apply patches that apply older and obsolete versions of my current files. &lt;/p&gt;
&lt;p&gt;Please review my post to confirm that the aforementioned 3 critical update warnings in Vulnerability Assessment is really a false positive. &lt;/p&gt;
&lt;p&gt;Again thank you for Blink Personal, it&amp;#39;s really a great piece of software. &lt;/p&gt;
&lt;p&gt;Thanks in advance. &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;</description></item><item><title>Audit ID 9826 Microsoft Visual Studio ATL Vulnerabilities (969706) - VS 2008 SD</title><link>http://forums.eeye.com/forums/thread/4997.aspx</link><pubDate>Wed, 21 Oct 2009 13:25:54 GMT</pubDate><guid isPermaLink="false">a21f7e33-d546-44ed-90ca-b1df844505d6:4997</guid><dc:creator>RAC_Reaper</dc:creator><slash:comments>5</slash:comments><comments>http://forums.eeye.com/forums/thread/4997.aspx</comments><wfw:commentRss>http://forums.eeye.com/forums/commentrss.aspx?SectionID=18&amp;PostID=4997</wfw:commentRss><description>&lt;p&gt;&amp;nbsp;I have been trying to figure this one out.&amp;nbsp; All my windows XP SP3 machines, the Scan says that file C$\Program Files\Microsoft Visual Studio 9.0\VC\ce\dll\x86\atl90.dll is version 9.0.21022.220 and should be at 9.0.30729.4154.&amp;nbsp; MS09-035 is installed as well as other KB&amp;#39;s associated&amp;nbsp;according to a WSUS report&amp;nbsp;.&amp;nbsp; Is this another type of 3rd party add in? How can I get rid of this vulnerability?&lt;/p&gt;</description></item><item><title>Internet Explorer Vulnerability - False Positive?</title><link>http://forums.eeye.com/forums/thread/4636.aspx</link><pubDate>Tue, 04 Aug 2009 00:19:13 GMT</pubDate><guid isPermaLink="false">a21f7e33-d546-44ed-90ca-b1df844505d6:4636</guid><dc:creator>jin356b</dc:creator><slash:comments>5</slash:comments><comments>http://forums.eeye.com/forums/thread/4636.aspx</comments><wfw:commentRss>http://forums.eeye.com/forums/commentrss.aspx?SectionID=18&amp;PostID=4636</wfw:commentRss><description>&lt;p&gt;I have recently installed the latest security update for IE7 on my network (Cumulative Security Update for Internet Explorer 7 (KB972260)). Now whenever I do a Retina scan on these machines, they report 2 High risk vulnerabilities:&lt;/p&gt;
&lt;p&gt;Microsoft Internet Explorer Cumulative Security Update (958215) - 2003&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Retina Audit ID: 7449&lt;br /&gt;Microsoft Internet Explorer Security Update (960714) - 2003&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Retina Audit ID: 7521&lt;/p&gt;
&lt;p&gt;or&lt;/p&gt;
&lt;p&gt;Microsoft Internet Explorer Cumulative Security Update (958215) - XP&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Retina Audit ID: 7448&lt;br /&gt;Microsoft Internet Explorer Security Update (960714) - XP&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Retina Audit ID: 7520&lt;/p&gt;
&lt;p&gt;These vulnerabilities are from 2008, and&amp;nbsp;probably obsolete. I run am running the most updated versions of Win2k3 SP2 and WinXP SP3. Has anyone else had this problem? Does anyone know if these are actually False Positives, or has Microsoft opened up an old vulnerability?&lt;/p&gt;
&lt;p&gt;Thanks&lt;/p&gt;</description></item><item><title>Easy way to compare scans?</title><link>http://forums.eeye.com/forums/thread/5107.aspx</link><pubDate>Sat, 07 Nov 2009 01:02:59 GMT</pubDate><guid isPermaLink="false">a21f7e33-d546-44ed-90ca-b1df844505d6:5107</guid><dc:creator>jimbo</dc:creator><slash:comments>4</slash:comments><comments>http://forums.eeye.com/forums/thread/5107.aspx</comments><wfw:commentRss>http://forums.eeye.com/forums/commentrss.aspx?SectionID=18&amp;PostID=5107</wfw:commentRss><description>&lt;p&gt;We run Retina scans every month and what I&amp;#39;d like to do is show management the progress that&amp;#39;s being made with IAV patching.&lt;/p&gt;
&lt;p&gt;Is there a way in Retina where I can compare scans?&lt;/p&gt;
&lt;p&gt;What I mean is:&lt;/p&gt;
&lt;p&gt;1st scan shows IAVA 2009-A-0001 is vulnerable on client1, client2, and client3.&lt;/p&gt;
&lt;p&gt;2nd scan shows the same IAVA 2009-A-0001 is vulnerable on client1 and client3.&lt;/p&gt;
&lt;p&gt;Looking at that, I can easily tell that the patch was applied to one client (client2).&amp;nbsp; But imagine having multiple IAVs on hundreds of clients.&amp;nbsp; Now you can see that manually doing this is too cumbersome.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;</description></item><item><title>null session and autorun update false positive findings</title><link>http://forums.eeye.com/forums/thread/4781.aspx</link><pubDate>Wed, 02 Sep 2009 13:39:02 GMT</pubDate><guid isPermaLink="false">a21f7e33-d546-44ed-90ca-b1df844505d6:4781</guid><dc:creator>osioniusx</dc:creator><slash:comments>12</slash:comments><comments>http://forums.eeye.com/forums/thread/4781.aspx</comments><wfw:commentRss>http://forums.eeye.com/forums/commentrss.aspx?SectionID=18&amp;PostID=4781</wfw:commentRss><description>&lt;p&gt;&amp;nbsp;I have a lot of these false positives. This means the system was not admin, or is there another possible problem? Thx.&lt;/p&gt;</description></item><item><title>Audit 3490</title><link>http://forums.eeye.com/forums/thread/4977.aspx</link><pubDate>Fri, 16 Oct 2009 13:34:25 GMT</pubDate><guid isPermaLink="false">a21f7e33-d546-44ed-90ca-b1df844505d6:4977</guid><dc:creator>vworthy</dc:creator><slash:comments>2</slash:comments><comments>http://forums.eeye.com/forums/thread/4977.aspx</comments><wfw:commentRss>http://forums.eeye.com/forums/commentrss.aspx?SectionID=18&amp;PostID=4977</wfw:commentRss><description>&lt;p&gt;I believe that I have my registry settings correctly set, but because this audit continues to show I am starting to doubt myself.&lt;/p&gt;
&lt;p&gt;Presently,&lt;/p&gt;
&lt;p&gt;I have set to audit the &amp;quot;everyone&amp;quot; group for failures and have the following checked: Set Value &amp;quot;Failed&amp;quot;, Create subkey &amp;quot;Failed&amp;quot;, and Delete &amp;quot;Failed&amp;quot;. I have Allow Ingeritable permissions from parent to propagate to this object selected both under Access Control Settings and Permission for hive.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;</description></item><item><title>Remote registry access</title><link>http://forums.eeye.com/forums/thread/5080.aspx</link><pubDate>Tue, 03 Nov 2009 01:36:38 GMT</pubDate><guid isPermaLink="false">a21f7e33-d546-44ed-90ca-b1df844505d6:5080</guid><dc:creator>bb93444</dc:creator><slash:comments>3</slash:comments><comments>http://forums.eeye.com/forums/thread/5080.aspx</comments><wfw:commentRss>http://forums.eeye.com/forums/commentrss.aspx?SectionID=18&amp;PostID=5080</wfw:commentRss><description>&lt;p&gt;I am having issues gaining remote registry&amp;nbsp;access even though known good credentials are used.&amp;nbsp; Remote Registry service has been verified&amp;nbsp;to be started&amp;nbsp;along with file and print services allowed.&amp;nbsp;&amp;nbsp;I am not sure what else is requried.&amp;nbsp; The computer being scanned is a&amp;nbsp;Windows 2003 member server.&amp;nbsp; Any&amp;nbsp;ideas on what to look for would be greatly appreciated.&amp;nbsp;&lt;/p&gt;</description></item><item><title>Retina Audit ID 5329</title><link>http://forums.eeye.com/forums/thread/4789.aspx</link><pubDate>Thu, 03 Sep 2009 15:00:28 GMT</pubDate><guid isPermaLink="false">a21f7e33-d546-44ed-90ca-b1df844505d6:4789</guid><dc:creator>jaws</dc:creator><slash:comments>4</slash:comments><comments>http://forums.eeye.com/forums/thread/4789.aspx</comments><wfw:commentRss>http://forums.eeye.com/forums/commentrss.aspx?SectionID=18&amp;PostID=4789</wfw:commentRss><description>&lt;p&gt;&amp;nbsp;Hi,&lt;/p&gt;
&lt;p&gt;Audit ID 5329: Ensures that all keys under HKLM\Software\Classes\AppId do not have a &amp;quot;RunAs&amp;quot; value.&lt;/p&gt;
&lt;p&gt;Retina identifies all items that have &amp;quot;RunAs&amp;quot;.&lt;/p&gt;
&lt;p&gt;I think this is only a problem if &amp;quot;RunAs&amp;quot; has a value other than Interactive User.&lt;/p&gt;
&lt;p&gt;If this is correct maybe a small modification to Audit 5329 --- RunAs exits and is not set to Interactive User.&lt;/p&gt;
&lt;p&gt;This would help eliminate false positives.&lt;/p&gt;
&lt;p&gt;Thanks,&lt;/p&gt;
&lt;p&gt;Jim&lt;/p&gt;</description></item><item><title>Audit ID's 958215 and 970714 </title><link>http://forums.eeye.com/forums/thread/5097.aspx</link><pubDate>Wed, 04 Nov 2009 18:35:45 GMT</pubDate><guid isPermaLink="false">a21f7e33-d546-44ed-90ca-b1df844505d6:5097</guid><dc:creator>RAC_Reaper</dc:creator><slash:comments>1</slash:comments><comments>http://forums.eeye.com/forums/thread/5097.aspx</comments><wfw:commentRss>http://forums.eeye.com/forums/commentrss.aspx?SectionID=18&amp;PostID=5097</wfw:commentRss><description>&lt;p&gt;&amp;nbsp;I got a recent update to the engine and vulnerability scanner.&amp;nbsp; I am now at version 5.10.20.2153.&lt;/p&gt;
&lt;p&gt;With this update these 2 vulnerabilities show are showing up on XP workstations.&amp;nbsp; Both check the version of file C$\WINDOWS\system32\mshtml.dll.&lt;/p&gt;
&lt;p&gt;Is there a fluke in the check?&amp;nbsp; These two audits were not showing up before.&lt;/p&gt;</description></item><item><title>Audit ID 10359 Clustered servers</title><link>http://forums.eeye.com/forums/thread/5056.aspx</link><pubDate>Fri, 30 Oct 2009 17:36:26 GMT</pubDate><guid isPermaLink="false">a21f7e33-d546-44ed-90ca-b1df844505d6:5056</guid><dc:creator>RAC_Reaper</dc:creator><slash:comments>5</slash:comments><comments>http://forums.eeye.com/forums/thread/5056.aspx</comments><wfw:commentRss>http://forums.eeye.com/forums/commentrss.aspx?SectionID=18&amp;PostID=5056</wfw:commentRss><description>&lt;p&gt;I have been&amp;nbsp;finding out more about 2003 Server clustering.&amp;nbsp; In&amp;nbsp;my&amp;nbsp;environment I have two&amp;nbsp;W2K3 servers that are clustered.&amp;nbsp; One&amp;#39;s called Martha, the other Stewart.&amp;nbsp;&amp;nbsp;The cluster is named Fred.&amp;nbsp; &amp;nbsp;Martha has IP 10.1.1.2, Stewart 10.1.1.3 and Fred has 10.1.1.4.&amp;nbsp; Martha and Stewart are not vulnerable to Audit 10359, but Fred reports that it is.&amp;nbsp; From looking what the scan finds, Retina is looking for a Registry key.&amp;nbsp; Since Fred is logically just a name, the scanner cannot find the key (found value is **keynotfound**).&amp;nbsp; &lt;/p&gt;
&lt;p&gt;Is there anyway&amp;nbsp;you can make the scanner not scan these types of IP&amp;#39;s (IP&amp;#39;s that are cluster names)?&lt;/p&gt;
&lt;p&gt;I could omit the IP from the scan.&amp;nbsp; That would probably be an easier solution.&lt;/p&gt;</description></item><item><title>Help Help Help - had to Uninstall Blink!</title><link>http://forums.eeye.com/forums/thread/5048.aspx</link><pubDate>Fri, 30 Oct 2009 05:51:06 GMT</pubDate><guid isPermaLink="false">a21f7e33-d546-44ed-90ca-b1df844505d6:5048</guid><dc:creator>Winifred</dc:creator><slash:comments>13</slash:comments><comments>http://forums.eeye.com/forums/thread/5048.aspx</comments><wfw:commentRss>http://forums.eeye.com/forums/commentrss.aspx?SectionID=18&amp;PostID=5048</wfw:commentRss><description>&lt;p&gt;Hi, all&lt;/p&gt;
&lt;p&gt;Today (10/29) got a note that Blink needed to be restarted to download overnight update.&amp;nbsp; Rebooted.&amp;nbsp; Blink couldn&amp;#39;t start.&amp;nbsp; Windows told me to go to Control Panel and under Programs -&amp;nbsp; right click to have Windows repair Blink (this worked before - some time ago.)&amp;nbsp; This time it did not work.&amp;nbsp; I rebooted several times and I kept getting a Blink message saying that I was using an invalid password - however I don&amp;#39;t have ANY password for Blink - nor anywhere, including logging in to Vista.&amp;nbsp; Another error message Blink gave me was that I was running another version of Blink which needed to be shutdown before startup version of Blink could start -&amp;nbsp; and &amp;#39;tho no Blink icon in my systray - Task Mgr did show Blink as running.&amp;nbsp; Lastly thru all this, I couldn&amp;#39;t get on the internet via my AOL dialup.&amp;nbsp; So I have uninstalled Blink and was then AOL got me online OK.&amp;nbsp; I would like to reinstall my paid version but have no idea how to do that.&amp;nbsp; Any help? ? ? ? ?&amp;nbsp;&amp;nbsp;&amp;nbsp; Thanks!&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;</description></item><item><title>Tech Support</title><link>http://forums.eeye.com/forums/thread/5050.aspx</link><pubDate>Fri, 30 Oct 2009 14:04:03 GMT</pubDate><guid isPermaLink="false">a21f7e33-d546-44ed-90ca-b1df844505d6:5050</guid><dc:creator>Winifred</dc:creator><slash:comments>3</slash:comments><comments>http://forums.eeye.com/forums/thread/5050.aspx</comments><wfw:commentRss>http://forums.eeye.com/forums/commentrss.aspx?SectionID=18&amp;PostID=5050</wfw:commentRss><description>&lt;p&gt;Hi&lt;/p&gt;
&lt;p&gt;Got an email bounced when directed to dr.support@eeye.com (address given for Blink tech support when I purchased.)&amp;nbsp; Does anyone have the correct email address for Blink tech support?&lt;/p&gt;</description></item><item><title>How to change my registry to follow Blink's instructions re kilbit of Microsoft KB240797? </title><link>http://forums.eeye.com/forums/thread/4993.aspx</link><pubDate>Tue, 20 Oct 2009 02:54:28 GMT</pubDate><guid isPermaLink="false">a21f7e33-d546-44ed-90ca-b1df844505d6:4993</guid><dc:creator>Winifred</dc:creator><slash:comments>1</slash:comments><comments>http://forums.eeye.com/forums/thread/4993.aspx</comments><wfw:commentRss>http://forums.eeye.com/forums/commentrss.aspx?SectionID=18&amp;PostID=4993</wfw:commentRss><description>&lt;p&gt;Can anyone actually walk me thru EXACTLY how to change my registry to
follow Blink&amp;#39;s instructions re kilbit of Microsoft KB240797?&amp;nbsp; I&amp;#39;ve
already backed up my registry following MS&amp;#39;s instructions - but I just
can&amp;#39;t figure out how to actulally do the registry killbit.&amp;nbsp; Thanks,
y&amp;#39;all!&lt;/p&gt;</description></item><item><title>Miscellaneous Sun JRE/JDK Multiple Vulnerabilities (20090804) - Windows - JRE 1.6.0   </title><link>http://forums.eeye.com/forums/thread/4668.aspx</link><pubDate>Fri, 07 Aug 2009 01:08:32 GMT</pubDate><guid isPermaLink="false">a21f7e33-d546-44ed-90ca-b1df844505d6:4668</guid><dc:creator>Winifred</dc:creator><slash:comments>15</slash:comments><comments>http://forums.eeye.com/forums/thread/4668.aspx</comments><wfw:commentRss>http://forums.eeye.com/forums/commentrss.aspx?SectionID=18&amp;PostID=4668</wfw:commentRss><description>&lt;p&gt;Hi, this appeared today as a high risk item.&amp;nbsp; Can anyone tell me which version of these I should get - or how to find out which version I need?&amp;nbsp; I&amp;#39;m not a techie and use Vista, if that helps.&lt;/p&gt;
&lt;p&gt; Windows

JRE/JDK 6.0: Upgrade to Update 15 or newer.&lt;/p&gt;
&lt;p&gt;
JRE/JDK 5.0: Upgrade to Update 20 or newer.
&lt;/p&gt;
&lt;p&gt;JRE/JDK 1.4.2: Upgrade to Update 22 or newer, or migrate to a newer version.
&lt;/p&gt;
&lt;p&gt;JRE/JDK 1.3.1: Upgrade to Update 26 or newer, or migrate to a newer version.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Thanks,&lt;/p&gt;
&lt;p&gt;Wini&lt;/p&gt;</description></item><item><title>Audit ID 7469 Microsoft Visual Basic 6.0 ActiveX Runtimes Code Execution (932349) </title><link>http://forums.eeye.com/forums/thread/4996.aspx</link><pubDate>Wed, 21 Oct 2009 13:01:32 GMT</pubDate><guid isPermaLink="false">a21f7e33-d546-44ed-90ca-b1df844505d6:4996</guid><dc:creator>RAC_Reaper</dc:creator><slash:comments>4</slash:comments><comments>http://forums.eeye.com/forums/thread/4996.aspx</comments><wfw:commentRss>http://forums.eeye.com/forums/commentrss.aspx?SectionID=18&amp;PostID=4996</wfw:commentRss><description>&lt;p&gt;&amp;nbsp;I have been reading other posts that deal with these active&amp;nbsp;X OCX&amp;nbsp;files and how 3rd party vendor are supposed to patch them.&lt;/p&gt;
&lt;p&gt;From my research, there is some discussion about msmask32.ocx version 6.0.84.18 not being vulnerable, but still flagging by a Retina scan.&amp;nbsp; Can you please verify vulnerable or not vulnerable?&lt;/p&gt;
&lt;p&gt;My issue seams to deal with any workstation with ARC GIS loaded.&amp;nbsp; ESRI released a patch that took care of 5 of the 6 OCX files, but I still get this one in a scan.&lt;/p&gt;</description></item><item><title>Sun JRE/JDK Multiple Vulnerabilities (20090804) - Windows - JRE 1.4.2</title><link>http://forums.eeye.com/forums/thread/4988.aspx</link><pubDate>Sun, 18 Oct 2009 21:24:29 GMT</pubDate><guid isPermaLink="false">a21f7e33-d546-44ed-90ca-b1df844505d6:4988</guid><dc:creator>vkundakci</dc:creator><slash:comments>3</slash:comments><comments>http://forums.eeye.com/forums/thread/4988.aspx</comments><wfw:commentRss>http://forums.eeye.com/forums/commentrss.aspx?SectionID=18&amp;PostID=4988</wfw:commentRss><description>&lt;p&gt;I am getting the above vulnerability audit starting a few days ago.&amp;nbsp; I do not have JRE 1.4.2 installed.&amp;nbsp; Verifying java version on my computer below:&lt;/p&gt;
&lt;p&gt;C:\&amp;gt;java -version&lt;br /&gt;java version &amp;quot;1.6.0_16&amp;quot;&lt;br /&gt;Java(TM) SE Runtime Environment (build 1.6.0_16-b01)&lt;br /&gt;Java HotSpot(TM) Client VM (build 14.2-b01, mixed mode, sharing)&lt;/p&gt;
&lt;p&gt;Any idas?&lt;/p&gt;
&lt;p&gt;The full audit message is below:&lt;/p&gt;
&lt;table style="font-family:Verdana;font-size:8pt;" cellpadding="1" cellspacing="0"&gt;

&lt;tr class="internal_row_alt"&gt;
&lt;td&gt;&lt;b&gt;BID&lt;/b&gt;&lt;/td&gt;
&lt;td&gt;35943, 35945, 35939, 35942, 35944&lt;/td&gt;
&lt;/tr&gt;
&lt;tr class="internal_row"&gt;
&lt;td&gt;&lt;b&gt;CVE&lt;/b&gt;&lt;/td&gt;
&lt;td&gt;CVE-2009-2676, CVE-2009-2625, CVE-2009-2674, 
CVE-2009-2671, CVE-2009-0217, CVE-2009-2670, CVE-2009-2673, CVE-2009-2675, 
CVE-2009-2672&lt;/td&gt;
&lt;/tr&gt;
&lt;tr class="internal_row_alt"&gt;
&lt;td&gt;&lt;b&gt;Description&lt;/b&gt;&lt;/td&gt;
&lt;td&gt;Sun Java Runtime Environment (JRE) and Java 
Development Kit (JDK) contain multiple vulnerabilities that could allow 
connections to arbitrary hosts, web session hijacking, username disclosure, 
execution of untrusted Java Web Start applications with elevated privileges 
(e.g. thus allowing permissions to local files, or execution of local 
applications), spoofing of XML digital signatures, spoofing/manipulation of 
security dialogs, cause denial of service conditions, and/or execution of 
arbitrary code (via multiple vectors).&lt;/td&gt;
&lt;/tr&gt;
&lt;tr class="internal_row"&gt;
&lt;td&gt;&lt;b&gt;How To Fix&lt;/b&gt;&lt;/td&gt;
&lt;td&gt;Install or apply the appropriate vendor-supplied 
fix:&lt;br /&gt;&lt;br /&gt;Note: JRE/JDK 1.4.x/1.3.x updates are available only through Sun 
Vintage Support or Java SE for Business contracts.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Windows&lt;/b&gt;&lt;br /&gt;
&lt;li&gt;JRE/JDK 6.0: Upgrade to Update 15 or newer.
&lt;/li&gt;
&lt;li&gt;JRE/JDK 5.0: Upgrade to Update 20 or newer.
&lt;/li&gt;
&lt;li&gt;JRE/JDK 1.4.2: Upgrade to Update 22 or newer, or migrate to a newer version.
&lt;/li&gt;
&lt;li&gt;JRE/JDK 1.3.1: Upgrade to Update 26 or newer, or migrate to a newer 
version.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Linux&lt;/b&gt;&lt;br /&gt;
&lt;/li&gt;
&lt;li&gt;JRE/JDK 6.0: Upgrade to Update 15 or newer.
&lt;/li&gt;
&lt;li&gt;JRE/JDK 5.0: Upgrade to Update 20 or newer.
&lt;/li&gt;
&lt;li&gt;JRE/JDK 1.4.2: Upgrade to Update 22 or newer, or migrate to a newer version.
&lt;/li&gt;
&lt;li&gt;JRE/JDK 1.3.1: Upgrade to Update 26 or newer, or migrate to a newer 
version.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Solaris&lt;/b&gt;&lt;br /&gt;
&lt;/li&gt;
&lt;li&gt;JRE/JDK 6.0: Upgrade to Update 15 or newer.
&lt;/li&gt;
&lt;li&gt;JRE/JDK 5.0: Upgrade to Update 20 or newer.
&lt;/li&gt;
&lt;li&gt;JRE/JDK 1.4.2: Upgrade to Update 22 or newer, or migrate to a newer version.
&lt;/li&gt;
&lt;li&gt;JRE/JDK 1.3.1: Upgrade to Update 26 or newer, or migrate to a newer 
version.&lt;/li&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr class="internal_row_alt"&gt;
&lt;td&gt;&lt;b&gt;Links&lt;/b&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="http://sunsolve.sun.com/search/document.do?assetkey=1-66-263429-1" target="_blank"&gt;Sun Alert - 263429&lt;/a&gt;&lt;br /&gt;&lt;a href="http://java.sun.com/javase/downloads/index_jdk5.jsp" target="_blank"&gt;Java 
Downloads - JRE/JDK 5 Update 20&lt;/a&gt;&lt;br /&gt;&lt;a href="http://java.sun.com/javase/6/webnotes/6u15.html" target="_blank"&gt;Release 
Notes - JRE 6 Update 15&lt;/a&gt;&lt;br /&gt;&lt;a href="http://sunsolve.sun.com/search/document.do?assetkey=1-66-263408-1" target="_blank"&gt;Sun Alert - 263408&lt;/a&gt;&lt;br /&gt;&lt;a href="http://sunsolve.sun.com/search/document.do?assetkey=1-66-263489-1" target="_blank"&gt;Sun Alert - 263489&lt;/a&gt;&lt;br /&gt;&lt;a href="http://secunia.com/advisories/36159" target="_blank"&gt;Secunia Advisory - 
36159&lt;/a&gt;&lt;br /&gt;&lt;a href="http://java.sun.com/javase/downloads/index.jsp" target="_blank"&gt;Java Downloads - JRE/JDK 6 Update 15&lt;/a&gt;&lt;br /&gt;&lt;a href="http://sunsolve.sun.com/search/document.do?assetkey=1-66-264648-1" target="_blank"&gt;Sun Alert - 264648&lt;/a&gt;&lt;br /&gt;&lt;a href="http://sunsolve.sun.com/search/document.do?assetkey=1-66-263488-1" target="_blank"&gt;Sun Alert - 263488&lt;/a&gt;&lt;br /&gt;&lt;a href="http://java.sun.com/j2se/1.5.0/ReleaseNotes.html#150_20" target="_blank"&gt;Release Notes - JRE 5 Update 20&lt;/a&gt;&lt;br /&gt;&lt;a href="http://sunsolve.sun.com/search/document.do?assetkey=1-66-263409-1" target="_blank"&gt;Sun Alert - 263409&lt;/a&gt;&lt;br /&gt;&lt;a href="http://sunsolve.sun.com/search/document.do?assetkey=1-66-263490-1" target="_blank"&gt;Sun Alert - 263490&lt;/a&gt;&lt;br /&gt;&lt;a href="http://sunsolve.sun.com/search/document.do?assetkey=1-66-263428-1" target="_blank"&gt;Sun Alert - 263428&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr class="internal_row"&gt;
&lt;td&gt;&lt;b&gt;Risk&lt;/b&gt;&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;

&lt;/table&gt;</description></item><item><title>Where are the manual installs?</title><link>http://forums.eeye.com/forums/thread/5001.aspx</link><pubDate>Thu, 22 Oct 2009 15:41:26 GMT</pubDate><guid isPermaLink="false">a21f7e33-d546-44ed-90ca-b1df844505d6:5001</guid><dc:creator>maaksel</dc:creator><slash:comments>2</slash:comments><comments>http://forums.eeye.com/forums/thread/5001.aspx</comments><wfw:commentRss>http://forums.eeye.com/forums/commentrss.aspx?SectionID=18&amp;PostID=5001</wfw:commentRss><description>&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;
 
&lt;tr style="height:12.75pt;"&gt;
&lt;td style="height:12.75pt;width:470pt;"&gt;Sun JRE/JDK
  Multiple Vulnerabilities (20090324) - Windows - JDK 1.4.2&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:12.75pt;"&gt;
&lt;td style="height:12.75pt;"&gt;Sun JRE/JDK Multiple Vulnerabilities
  (20090324) - Windows - JDK 1.5.0&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:12.75pt;"&gt;
&lt;td style="height:12.75pt;"&gt;Sun JRE/JDK Multiple Vulnerabilities
  (20090324) - Windows - JRE 1.6.0&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:12.75pt;"&gt;
&lt;td style="height:12.75pt;"&gt;Sun JRE/JDK Multiple Vulnerabilities
  (20090804) - Windows - JDK 1.4.2&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:12.75pt;"&gt;
&lt;td style="height:12.75pt;"&gt;Sun JRE/JDK Multiple Vulnerabilities
  (20090804) - Windows - JDK 1.5.0&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:12.75pt;"&gt;
&lt;td style="height:12.75pt;"&gt;Sun JRE/JDK Multiple Vulnerabilities
  (20090804) - Windows - JRE 1.4.2&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:12.75pt;"&gt;
&lt;td style="height:12.75pt;"&gt;Sun JRE/JDK Multiple Vulnerabilities
  (20090804) - Windows - JRE 1.5.0&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style="height:12.75pt;"&gt;
&lt;td style="height:12.75pt;"&gt;
&lt;p&gt;Sun JRE/JDK Multiple Vulnerabilities
  (20090804) - Windows - JRE 1.6.0&lt;/p&gt;
&lt;p&gt;Our enterprise has over 900 servers, these have all been found to be out of date patches through Retina. &amp;nbsp;I have been trying to find the download for the manual install so I can script it out and &amp;#39;just get it done&amp;#39; as I was directed by our CIO.&lt;/p&gt;
&lt;p&gt;Updating/maintaining will be done/planned in the next coming weeks, however i need to have all the patched by 6am 10/24&lt;/p&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;</description></item><item><title>Remedy for vulnerability items, “Microsoft Visual Basic 6.0 ActiveX Runtimes Code Execution (932349)”?</title><link>http://forums.eeye.com/forums/thread/3800.aspx</link><pubDate>Mon, 12 Jan 2009 05:33:05 GMT</pubDate><guid isPermaLink="false">a21f7e33-d546-44ed-90ca-b1df844505d6:3800</guid><dc:creator>rhkohl</dc:creator><slash:comments>23</slash:comments><comments>http://forums.eeye.com/forums/thread/3800.aspx</comments><wfw:commentRss>http://forums.eeye.com/forums/commentrss.aspx?SectionID=18&amp;PostID=3800</wfw:commentRss><description>&lt;p&gt;In the Blink-Personal Vulnerability Assessment Report, I have four, high-risk items titled the above -- one for each of comct232, mscomct2, msdatgrd, msmask32 -- all citing MS08-070, KB932349, and Secunia Advisories 26534 and 31498.&amp;nbsp; I found these 4 names as .ocx files in my Windows\system32 folder.&amp;nbsp; I read where these are Microsoft Visual Basic 6.0 Runtime Extended Files (ActiveX Controls) which are distributed by developers with their VB6 applications.&amp;nbsp; These might well also have come OEM with the computer (?).&amp;nbsp; The date of the one I checked was 1998 and, using Notepad, it looked to be something straight from Microsoft with copyright notice and version number.&amp;nbsp; The Microsoft-Update application will not offer an update that addresses these items in any way.&amp;nbsp; Using either MS08-070 (and looking in FAQ&amp;rsquo;s) or the link (to Microsoft) in the Secunia advisories results in the same download, the &amp;ldquo;Cumulative Update for Microsoft Visual Basic 6.0 SP6 (KBnnnnnn)&amp;rdquo; where nnnnnnn depends on the link used.&amp;nbsp; I do not have MS Visual Basic 6 on my computer and sure enough, when I went to install either download I got the message, &amp;ldquo;In order to install Cumulative Update for Microsoft Visual Basic 6.0 SP6 (KBnnnnnn) you must have Microsoft Visual Basic 6.0 Product installed&amp;rdquo;.&amp;nbsp; This download appears to be for the developer so that his/her future products do not have the vulnerability.&amp;nbsp; So I still have these vulnerabilities on my computer, and they are of unknown use.&amp;nbsp; What now?&lt;br /&gt;&lt;br /&gt;Does anyone have any thoughts?&lt;/p&gt;
&lt;p&gt;&lt;br /&gt;&lt;/p&gt;</description></item><item><title>Retina came up with vulnerabilities after Windows Update ran and patched system</title><link>http://forums.eeye.com/forums/thread/4966.aspx</link><pubDate>Tue, 13 Oct 2009 18:54:36 GMT</pubDate><guid isPermaLink="false">a21f7e33-d546-44ed-90ca-b1df844505d6:4966</guid><dc:creator>jdeitel</dc:creator><slash:comments>3</slash:comments><comments>http://forums.eeye.com/forums/thread/4966.aspx</comments><wfw:commentRss>http://forums.eeye.com/forums/commentrss.aspx?SectionID=18&amp;PostID=4966</wfw:commentRss><description>&lt;p&gt;Reposting this here as I do not think troubleshooting is the correct forum:&lt;/p&gt;
&lt;p&gt;Ok, so this is the first time I&amp;#39;ve had an issue like this. I scanned a few servers this morning with updated Audits and I came up with a few vulnerabilities. Well I decided to do a windows update on all of the boxes and now I&amp;#39;ve got Cumulative IE secuirty updates popping all over my reports. The IE updates and ActiveX killbits appeared &amp;quot;old&amp;quot; but when I looked for more information the site said it was updated as of 10/13/2009.... &lt;/p&gt;
&lt;p&gt;I&amp;#39;m going to rollback all of the updates I performed but has anyone else encountered something along the same lines? MS Update screwy?&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Thanks&lt;/p&gt;</description></item><item><title>Dual-Homed Retina 651 Appliance</title><link>http://forums.eeye.com/forums/thread/4954.aspx</link><pubDate>Sun, 11 Oct 2009 17:43:07 GMT</pubDate><guid isPermaLink="false">a21f7e33-d546-44ed-90ca-b1df844505d6:4954</guid><dc:creator>mwhittek</dc:creator><slash:comments>2</slash:comments><comments>http://forums.eeye.com/forums/thread/4954.aspx</comments><wfw:commentRss>http://forums.eeye.com/forums/commentrss.aspx?SectionID=18&amp;PostID=4954</wfw:commentRss><description>&lt;p&gt;Is it possible to configure the 651 appliance as a dual-homed system?&amp;nbsp; I would like for the appliance to be on one subnet for scanning purposes, and another subnet for acquiring updates.&amp;nbsp; The appliance has two network interfaces, but the documentation for the appliance is virtually non-existent.&lt;/p&gt;</description></item><item><title>External Vulnerability Assesment (Scanner Placement and Other Methods)</title><link>http://forums.eeye.com/forums/thread/4912.aspx</link><pubDate>Fri, 02 Oct 2009 15:50:17 GMT</pubDate><guid isPermaLink="false">a21f7e33-d546-44ed-90ca-b1df844505d6:4912</guid><dc:creator>ny101880</dc:creator><slash:comments>9</slash:comments><comments>http://forums.eeye.com/forums/thread/4912.aspx</comments><wfw:commentRss>http://forums.eeye.com/forums/commentrss.aspx?SectionID=18&amp;PostID=4912</wfw:commentRss><description>&lt;p&gt;Hi Everyone,&lt;br /&gt;&lt;br /&gt;I wanted to ask your opinion about vulnerability assessment to a corporate network&amp;#39;ss external asset (Located in the DMZ, Firewalls).&lt;br /&gt;&lt;br /&gt;Strategy: We plan to put the scanner outside of the corporate network (broadband connection in the house) to do the scan&lt;br /&gt;Options: rent a linux server from any hosting company to do the scan&lt;br /&gt;&lt;br /&gt;Difficulties:&lt;br /&gt;1. If this is our strategy, are we able to succeed in identifying faster the vulnerability to our corporate network (External Assets located in the DMZ)?&lt;br /&gt;&lt;br /&gt;2. What scanning method is best to be used (Unattenticated - Hacker Perspective) or Authneticated (Im not sure of the risk it will implicate)?&lt;br /&gt;3. What are the other optionsan suggest we can improve the quality of the result&lt;br /&gt;&lt;br /&gt;Im hoping you can share something on this.&lt;br /&gt;&lt;/p&gt;</description></item><item><title>General Retina Network Scan Question</title><link>http://forums.eeye.com/forums/thread/4809.aspx</link><pubDate>Tue, 08 Sep 2009 15:35:48 GMT</pubDate><guid isPermaLink="false">a21f7e33-d546-44ed-90ca-b1df844505d6:4809</guid><dc:creator>guest09</dc:creator><slash:comments>2</slash:comments><comments>http://forums.eeye.com/forums/thread/4809.aspx</comments><wfw:commentRss>http://forums.eeye.com/forums/commentrss.aspx?SectionID=18&amp;PostID=4809</wfw:commentRss><description>&lt;p&gt;Hi,&lt;/p&gt;
&lt;p&gt;I am currently evaluating the Retina Network Scan product including the VMS Export Wizard. I was wondering if there is a way to run the VMS Export Wizard from the command-line.&lt;/p&gt;
&lt;p&gt;Thanks!&lt;/p&gt;</description></item><item><title>Adobe Flash Player shows up on Vulnerability Checklist, but latest version is installed!</title><link>http://forums.eeye.com/forums/thread/1641.aspx</link><pubDate>Sat, 03 Nov 2007 07:05:07 GMT</pubDate><guid isPermaLink="false">a21f7e33-d546-44ed-90ca-b1df844505d6:1641</guid><dc:creator>rhkohl</dc:creator><slash:comments>3</slash:comments><comments>http://forums.eeye.com/forums/thread/1641.aspx</comments><wfw:commentRss>http://forums.eeye.com/forums/commentrss.aspx?SectionID=18&amp;PostID=1641</wfw:commentRss><description>&lt;p&gt;&amp;quot;Adobe Flash Player Multiple Vulnerabilities&amp;quot; shows up on the current, Blink-Personal, security checklist (with the &amp;quot;How to Fix&amp;quot; being &amp;quot;Upgrade A_ F_P_ to version 9...&amp;quot;, but prior to running this vulnerability assesment, I&amp;nbsp;downloaded version 9.0.47.0 (the latest) from the Adobe site and manually installed it,&amp;nbsp;getting a sub-window indicating a successful installation.&amp;nbsp;&amp;nbsp; In Control Panel, Add/Remove lists &amp;quot;Adobe Flash Player&amp;quot; and &amp;quot;Support Information&amp;quot;&amp;nbsp;in that list item&amp;nbsp;shows that the version is indeed 9.0.47.0.&lt;/p&gt;
&lt;p&gt;It would seem that there is something wrong with this item being in the Blink security checklist.&amp;nbsp; [There is one wrinkle, however, that&amp;nbsp;I do not understand, and that is that I can find no flash9.ocx file anywhere on C: (which I had a hunch I should find), but&amp;nbsp;I do have a Flash8.ocx file in C:\Windows\system32\Macromed\Flash.]&lt;/p&gt;
&lt;p&gt;Anyone&amp;#39;s thoughts would be appreciated.&lt;/p&gt;</description></item><item><title>Openoffice 3.1.1 not recognized</title><link>http://forums.eeye.com/forums/thread/4805.aspx</link><pubDate>Mon, 07 Sep 2009 03:24:17 GMT</pubDate><guid isPermaLink="false">a21f7e33-d546-44ed-90ca-b1df844505d6:4805</guid><dc:creator>vkundakci</dc:creator><slash:comments>7</slash:comments><comments>http://forums.eeye.com/forums/thread/4805.aspx</comments><wfw:commentRss>http://forums.eeye.com/forums/commentrss.aspx?SectionID=18&amp;PostID=4805</wfw:commentRss><description>&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Recently Openoffice 3.1.1 started to come up as vulnerable for CVE-2009-0200 and CVE-2009-0201.&amp;nbsp; Supposedly the buffer overflow problems were fixed in this release.&amp;nbsp; The report below mistakenly indicates that the problem is fixed in 3.3.1.&amp;nbsp; Maybe the version test has the same error.&lt;/p&gt;
&lt;table style="font-family:Verdana;font-size:8pt;" cellpadding="1" cellspacing="0"&gt;

&lt;tr class="internal_row_alt"&gt;
&lt;td&gt;&lt;b&gt;BID&lt;/b&gt;&lt;/td&gt;
&lt;td&gt;36200&lt;/td&gt;
&lt;/tr&gt;
&lt;tr class="internal_row"&gt;
&lt;td&gt;&lt;b&gt;CVE&lt;/b&gt;&lt;/td&gt;
&lt;td&gt;CVE-2009-0200, CVE-2009-0201&lt;/td&gt;
&lt;/tr&gt;
&lt;tr class="internal_row_alt"&gt;
&lt;td&gt;&lt;b&gt;Description&lt;/b&gt;&lt;/td&gt;
&lt;td&gt;OpenOffice contains mutliple heap-based buffer 
overflows when handling documents containing malformed Word document tables. 
Successful exploitation could allow execution of arbitrary code or could cause 
the application to crash.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr class="internal_row"&gt;
&lt;td&gt;&lt;b&gt;How To Fix&lt;/b&gt;&lt;/td&gt;
&lt;td&gt;Upgrade OpenOffice to version 3.3.1 or 
newer.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr class="internal_row_alt"&gt;
&lt;td&gt;&lt;b&gt;Links&lt;/b&gt;&lt;/td&gt;
&lt;td&gt;&lt;a href="http://secunia.com/advisories/35036" target="_blank"&gt;Secunia Advisory - 35036&lt;/a&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr class="internal_row"&gt;
&lt;td&gt;&lt;b&gt;Risk&lt;/b&gt;&lt;/td&gt;
&lt;td&gt;High&lt;/td&gt;
&lt;/tr&gt;

&lt;/table&gt;
&lt;table style="height:222px;" class="internal_window " cellpadding="1" cellspacing="0"&gt;
&lt;/table&gt;</description></item><item><title>Retina Scan suddenly finding missing MS Security Patches from 2005/6/7 </title><link>http://forums.eeye.com/forums/thread/4800.aspx</link><pubDate>Sat, 05 Sep 2009 14:30:51 GMT</pubDate><guid isPermaLink="false">a21f7e33-d546-44ed-90ca-b1df844505d6:4800</guid><dc:creator>froglips</dc:creator><slash:comments>10</slash:comments><comments>http://forums.eeye.com/forums/thread/4800.aspx</comments><wfw:commentRss>http://forums.eeye.com/forums/commentrss.aspx?SectionID=18&amp;PostID=4800</wfw:commentRss><description>&lt;p&gt;&amp;nbsp;We run Retina Scan (versions: Engine (5.10.17) and the Audit is (2132)) weekly, and download the latest&amp;nbsp;Audit prior to doing so. Our current&amp;nbsp;OS is Windows XP SP2.&amp;nbsp;This morning we downloaded the current Audit, and all of a sudden we are now missing the following patches:&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;IE Explorer Cumulative Patch for up to 6.0 2003-A-0014(3)&lt;/p&gt;
&lt;p&gt;SMB Remote Code Execution 2005-T-0019&lt;/p&gt;
&lt;p&gt;TCP/IP Vulnerabilities 2005-B-0012&lt;/p&gt;
&lt;p&gt;Outlook Express Cumulative Patch 837009&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Can anyone tell us why this may be happening?&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Also, the following problem exists, which a resolution has never been found for:&lt;/p&gt;
&lt;p&gt;JPEG Processing GDI+ Buffer Overflow 2004-A-0015&lt;/p&gt;
&lt;p&gt;Any help on this would be GREATLY appreciated as well.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Thanks for all of your time and help.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Sincerely,&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;</description></item></channel></rss>