|
 |
|
Mac OS X Java Multiple Vulnerabilities
|
|
|
|
|
Secunia Advisory:
|
SA28115
|
|
|
Release Date:
|
2007-12-17
|
|
|
Critical:
|

Highly critical
|
|
Impact:
|
Security Bypass Privilege escalation DoS System access
|
|
Where:
|
From remote
|
|
Solution Status:
|
Vendor Patch
|
|
| OS: | Apple Macintosh OS X
|
|
| | CVE reference: | CVE-2006-4339 (Secunia mirror) CVE-2006-6731 (Secunia mirror) CVE-2006-6736 (Secunia mirror) CVE-2006-6745 (Secunia mirror) CVE-2007-0243 (Secunia mirror) CVE-2007-2435 (Secunia mirror) CVE-2007-2788 (Secunia mirror) CVE-2007-2789 (Secunia mirror) CVE-2007-3004 (Secunia mirror) CVE-2007-3005 (Secunia mirror) CVE-2007-3503 (Secunia mirror) CVE-2007-3504 (Secunia mirror) CVE-2007-3655 (Secunia mirror) CVE-2007-3698 (Secunia mirror) CVE-2007-3922 (Secunia mirror) CVE-2007-4381 (Secunia mirror) CVE-2007-5232 (Secunia mirror) CVE-2007-5862 (Secunia mirror)
|
|
|
Want to know the next time vulnerabilities are fixed in this product? - Companies can be alerted via email and SMS! |
|
|
Description: Some vulnerabilities have been reported and acknowledged in Mac OS X, which can be exploited by malicious people to bypass certain security restrictions, conduct cross-site scripting attacks, to cause a DoS (Denial of Service), or to compromise a user's system.
1) An error in Java due to an improper access check can be exploited via a specially crafted Java applet to add or remove items from a user's Keychain, without prompting the user.
This vulnerability affects Mac OS X versions prior to 10.5.
2) Some vulnerabilities in Java 1.4 and J2SE 5.0 can be exploited to bypass certain security restrictions, conduct cross-site scripting attacks, to cause a DoS (Denial of Service), or to compromise a user's system.
For more information:
SA21709
SA23398
SA23445
SA23757
SA25069
SA25295
SA25769
SA25823
SA25981
SA26015
SA26402
SA27009
These vulnerabilities are reported in Mac OS X 10.4.10 and Mac OS X Server 10.4.10. Mac OS X v10.5 is reportedly not affected.
Solution: Update to Java Release 6 for Mac OS X 10.4.
Java for Mac OS X 10.4, Release 6:
http://www.apple.com/support/downloads/javaformacosx104release6.html
Provided and/or discovered by: 1) The vendor credits Bruno Harbulot, University of Manchester.
Original Advisory: Apple:
http://docs.info.apple.com/article.html?artnum=307177
Other References: SA21709:
http://secunia.com/advisories/21709/
SA23398:
http://secunia.com/advisories/23398/
SA23445:
http://secunia.com/advisories/23445/
SA23757:
http://secunia.com/advisories/23757/
SA25069:
http://secunia.com/advisories/25069/
SA25295:
http://secunia.com/advisories/25295/
SA25769:
http://secunia.com/advisories/25769/
SA25823:
http://secunia.com/advisories/25823/
SA25981:
http://secunia.com/advisories/25981/
SA26015:
http://secunia.com/advisories/26015/
SA26402:
http://secunia.com/advisories/26402/
SA27009:
http://secunia.com/advisories/27009/
|
|
|
|
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|
|
|
|
121 Related Secunia Security Advisories, displaying 10
|
|
|
1. Mac OS X Security Update Fixes Multiple Vulnerabilities
|
|
2. Apple Mac OS X "ipcomp6_input()" Denial of Service
|
|
3. Apple Mac OS X Security Update Fixes Multiple Vulnerabilities
|
|
4. Apple Mac OS X Security Update Fixes Multiple Vulnerabilities
|
|
5. Mac OS X "cs_validate_page()" Local Denial of Service
|
|
6. Mac OS X vpnd Denial of Service Vulnerability
|
|
7. Mac OS X Local Denial of Service Vulnerability
|
|
8. Apple Mail Command Execution Vulnerability
|
|
9. Apple Mac OS X Application Firewall Weaknesses and Security Issue
|
|
10. Apple Mac OS X Security Update Fixes Multiple Vulnerabilities
|
Show all related advisories
|
|
|
Send Feedback to Secunia
|
|
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.
|
|
|
|

|
 |
Secunia PSI Scan | Patch | Track Free Download
|
|
|
Secunia Poll
|
|
|
|
|
 |
|
|
Most Popular Advisories
|
|
|
|
|
|