Apple Java for Mac OS X Multiple Vulnerabilities
RISK: Extremely High Risk
TYPE: Operating Systems - Mac OS
Multiple vulnerabilities have been identified in Java for Mac OS X, which can be exploited by malicious people to compromise a vulnerable system.
Note: Exploit code is publicly available.
[13/4/2012 Update]
Apple published a new Java security update (Java for OS X Lion 2012-003) to remove the most common variants of the Flashback malware, and configure the Java web plug-in to disable the automatic execution of Java applets.
Impact
- Remote Code Execution
System / Technologies affected
- Mac OS X v10.6.8
- Mac OS X Server v10.6.8
- OS X Lion v10.7.3
- Lion Server v10.7.3
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Apply Apple Security Updates
Vulnerability Identifier
- CVE-2011-3563
- CVE-2011-5035
- CVE-2012-0497
- CVE-2012-0498
- CVE-2012-0499
- CVE-2012-0500
- CVE-2012-0501
- CVE-2012-0502
- CVE-2012-0503
- CVE-2012-0505
- CVE-2012-0506
- CVE-2012-0507
Source
Related Link
Share with