|
Mac OS X Security Update Fixes Multiple Vulnerabilities
|
|
Secunia Advisory:
|
SA10959
|
|
|
Release Date:
|
2004-02-24
|
|
Last Update:
|
2004-02-25
|
|
Popularity:
|
19,071 views
|
|
|
Critical:
|
 Moderately critical
|
|
Impact:
|
Exposure of system information Exposure of sensitive information DoS System access
|
|
Where:
|
From remote
|
|
Solution Status:
|
Vendor Patch
|
|
| OS: | Apple Macintosh OS X
|
|
|
Secunia CVSS-2 Score:
|
Available in Secunia business solutions
|
|
|
Subscribe:
|
Instant alerts on relevant vulnerabilities
|
|
| Advisory Content (Page 1 of 3) | [ 1 ] [ 2 ] [ 3 ] | |
|
Description: Multiple vulnerabilities have been discovered in Apple Mac OS X, where some of the specified issues can be exploited to gain knowledge of sensitive information, cause a DoS (Denial of Service), and potentially compromise a vulnerable system.
1) An unspecified vulnerability exists in the CoreFoundation notification logging.
2) An unspecified vulnerability exists in the DiskArbitration when handling initialisation of writeable removable media.
3) An unspecified vulnerability in exists in IPSec while checking key exchanges.
4) An assert error in QuickTime Streaming Server can be exploited by malicious people to cause a DoS. See the following advisory for more information:
SA10956
5) An unspecified vulnerability exists in Safari when displaying URLs in the status bar.
6) Multiple vulnerabilities in tcpdump can potentially be exploited by malicious people to cause a DoS or compromise a vulnerable system. See the following advisory for more information:
SA10636
7) A format string error in the "option_error()" function in pppd when handling command line arguments can be exploited by malicious, local users to read arbitrary memory accessible by the process. This may potentially expose PAP/CHAP authentication credentials if a system runs as a PPP server.
Change Page: [ 1 ] [ 2 ] [ 3 ]
|
|
|
Track this Secunia Advisory
|
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.
|
|
|
About this Secunia Advisory
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|