|
Mac OS X Java Multiple Vulnerabilities
|
|
Secunia Advisory:
|
SA28115
|
|
|
Release Date:
|
2007-12-17
|
|
Popularity:
|
8,576 views
|
|
|
Critical:
|
 Highly critical
|
|
Impact:
|
Security Bypass Privilege escalation DoS System access
|
|
Where:
|
From remote
|
|
Solution Status:
|
Vendor Patch
|
|
| OS: | Apple Macintosh OS X
|
|
|
Subscribe:
|
Instant alerts on relevant vulnerabilities
|
|
| CVE reference: | CVE-2006-4339 CVE-2006-6731 CVE-2006-6736 CVE-2006-6745 CVE-2007-0243 CVE-2007-2435 CVE-2007-2788 CVE-2007-2789 CVE-2007-3004 CVE-2007-3005 CVE-2007-3503 CVE-2007-3504 CVE-2007-3655 CVE-2007-3698 CVE-2007-3922 CVE-2007-4381 CVE-2007-5232 CVE-2007-5862
|
|
Description: Some vulnerabilities have been reported and acknowledged in Mac OS X, which can be exploited by malicious people to bypass certain security restrictions, conduct cross-site scripting attacks, to cause a DoS (Denial of Service), or to compromise a user's system.
1) An error in Java due to an improper access check can be exploited via a specially crafted Java applet to add or remove items from a user's Keychain, without prompting the user.
This vulnerability affects Mac OS X versions prior to 10.5.
2) Some vulnerabilities in Java 1.4 and J2SE 5.0 can be exploited to bypass certain security restrictions, conduct cross-site scripting attacks, to cause a DoS (Denial of Service), or to compromise a user's system.
For more information:
SA21709
SA23398
SA23445
SA23757
SA25069
SA25295
SA25769
SA25823
SA25981
SA26015
SA26402
SA27009
These vulnerabilities are reported in Mac OS X 10.4.10 and Mac OS X Server 10.4.10. Mac OS X v10.5 is reportedly not affected.
Solution: Update to Java Release 6 for Mac OS X 10.4.
Java for Mac OS X 10.4, Release 6:
http://www.apple.com/support/downloads/javaformacosx104release6.html
Provided and/or discovered by: 1) The vendor credits Bruno Harbulot, University of Manchester.
Original Advisory: Apple:
http://docs.info.apple.com/article.html?artnum=307177
Other References: SA21709:
http://secunia.com/advisories/21709/
SA23398:
http://secunia.com/advisories/23398/
SA23445:
http://secunia.com/advisories/23445/
SA23757:
http://secunia.com/advisories/23757/
SA25069:
http://secunia.com/advisories/25069/
SA25295:
http://secunia.com/advisories/25295/
SA25769:
http://secunia.com/advisories/25769/
SA25823:
http://secunia.com/advisories/25823/
SA25981:
http://secunia.com/advisories/25981/
SA26015:
http://secunia.com/advisories/26015/
SA26402:
http://secunia.com/advisories/26402/
SA27009:
http://secunia.com/advisories/27009/
|
|
|
Track this Secunia Advisory
|
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.
|
|
|
About this Secunia Advisory
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|