[Update] Saint Vulnerability Scanner 6.7.2 available
Monday 4 February 2008
SAINT is the Security Administrator’s Integrated Network Tool. It is used to non-intrusively detect security vulnerabilities on any remote target, including servers, workstations, networking devices, and other types of nodes. It will also gather information such as operating system types and open ports. The SAINT graphical user interface provides access to SAINT’s data management, scan configuration, scan scheduling, and data analysis capabilities through a web browser. Different aspects of the scan results are presented in hyperlinked HTML pages, and reports on complete scan results can be generated and savedNew vulnerability checks in version 6.7.2:
MS Rich Textbox Control Savefile vulnerability
MS Visual FoxPro DoCmd ActiveX vulnerability
yaSSL vulnerability in MySQL
Jetty Double Slash URI Information Disclosure Vulnerability
JustSystems Ichitaro JSFC.dll buffer overflow vulnerability
QuickTime HTTP Error Response buffer overflow vulnerability
McAfee E-Business Server vulnerability
AOL Radio AmpX vulnerability
TSM Express vulnerability
PostgreSQL vulnerabilities
QuickTime vulnerabilities fixed by version 7.4
Drupal vulnerability
MadWifi
Apache module vulnerabilities
Gateway Web Launch ActiveX vulnerabilities
SAP MaxDB cons.exe command injection vulnerability
MS Excel file handling code execution vulnerability
Tectia SSH Server privilege elevation vulnerability
Cisco UCM CTLProvider heap overflow vulnerability
Oracle Database Critical Patch Update
security bypass and cross-site scripting vulnerabilities in Horde application framework and IMP Webmail
security bypass vulnerabilities in Horde Turba Contact Manager, Nag, Mnemo, Kronolith
macrovision FLEXNet ActiveX control vulnerability
UTorrent peers window remote denial of service vulnerability
Citadel SMTP buffer overflow
Citrix Presentation Server IMA buffer overflow vulnerability
Winamp Ultravox vulnerabilities
Crystal Reports Enterprise Tree ActiveX Control buffer overflow
Tivoli Provisioning Manager HTTP server bo vulnerability
Member Area System remote file include (view_func.php)
Gradman directory traversal (info.php)
New exploits in this version:
BrightStor ARCserve LGServer rxsUseLicenseIni exploit
Novell GroupWise Client IMG SRC exploit
MaxDB cons.exe command injection exploit
Microsoft Excel exploit
Microsoft DirectX SAMI parser exploit
Tivoli Provisioning Manager for OS Deployment exploit
POSTSCRIPTUM
RELATED ARTICLES
Automated Exploiter, Saint, Vulnerability Scanner,
15 August 2008 : Saint 6.8 released
31 July 2008 : Saint Vulnerability Scanner updated to 6.7.14
17 July 2008 : Saint Scanner 6.7.13 released
17 June 2008 : SAINT® 6.7.11 Released
6 June 2008 : SAINT® 6.7.10 Released
Security Dashboard





