|
Mac OS X Security Update Fixes Multiple Vulnerabilities
|
|
Secunia Advisory:
|
SA14005
|
|
|
Release Date:
|
2005-01-26
|
|
Last Update:
|
2005-02-01
|
|
Popularity:
|
15,652 views
|
|
|
Critical:
|
 Highly critical
|
|
Impact:
|
Security Bypass Cross Site Scripting Spoofing Exposure of system information Exposure of sensitive information Privilege escalation System access
|
|
Where:
|
From remote
|
|
Solution Status:
|
Vendor Patch
|
|
| OS: | Apple Macintosh OS X
|
|
|
Secunia CVSS-2 Score:
|
Available in Secunia business solutions
|
|
|
Subscribe:
|
Instant alerts on relevant vulnerabilities
|
|
| Advisory Content (Page 1 of 3) | [ 1 ] [ 2 ] [ 3 ] | |
|
Description: Apple has issued a security update for Mac OS X, which fixes various vulnerabilities.
1) The "at" family of utilities ("at", "atrm", "batch", "atq", and "atrun") does not drop privileges properly. This can be exploited to delete arbitrary files, execute arbitrary commands with escalated privileges, or read the contents of arbitrary files.
The vulnerability has been reported in Mac OS X 10.3.4 (Darwin kernel xnu-517.7.7) and has been confirmed in Mac OS X 10.3.7 (Darwin kernel xnu-517.9.5). Other versions may also be affected.
2) A boundary error in the ColorSync component when processing ICC color profiles can be exploited to cause a heap-based buffer overflow. This allows execution of arbitrary code via a specially crafted ICC color profile.
3) Various vulnerabilities in the libxml2 component can potentially be exploited to compromise a vulnerable system.
For more information:
SA13000
4) An information disclosure weakness in the Mail component makes it possible to determine the system from which an email has been sent. The problem is that an identifier associated with the Ethernet networking hardware is included in the "Message-ID" header.
5) Multiple vulnerabilities in PHP can be exploited to e.g. cause a DoS (Denial of Service) or execute arbitrary code.
For more information:
SA12064
SA13481
6) A vulnerability in Safari can be exploited by malicious people to spoof the content of web sites.
For more information:
SA13252
7) A vulnerability in SquirrelMail can be exploited by malicious people to conduct script insertion attacks.
For more information:
SA13155
Change Page: [ 1 ] [ 2 ] [ 3 ]
|
|
|
Track this Secunia Advisory
|
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.
|
|
|
About this Secunia Advisory
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|