Apple Mac OS X Code Execution and Security Bypass Vulnerabilities
RISK: Medium Risk
Multiple vulnerabilities have been identified in Apple Mac OS X, which could be exploited by remote or local attackers to disclose sensitive information, bypass security restrictions, cause a denial of service or compromise an affected system. These issues are caused by out-of-bounds memory access issues, input validation errors, buffer overflows, uninitialized memory access issues, integer overflows, uninitialized pointers, implementation issues, format string errors, and logic and synchronization issues in bzip2, CFNetwork, ColorSync, CoreTypes, Dock, Image RAW, ImageIO, Kernel, launchd, Login Window, MobileMe, Networking, and XQuery.
Impact
- Denial of Service
- Remote Code Execution
- Security Restriction Bypass
- Information Disclosure
System / Technologies affected
- Mac OS X version 10.4.11 and prior
- Mac OS X Server version 10.4.11 and prior
- Mac OS X versions 10.5 through 10.5.7
- Mac OS X Server versions 10.5 through 10.5.7
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Update to Mac OS X v10.5.8 or apply Apple Security Update 2009-003 :
http://www.apple.com/support/downloads/ - Security Update 2009-003 (Tiger Intel):
http://support.apple.com/downloads/DL872/en_US/SecUpd2009-003Intel.dmg - Security Update 2009-003 (Server Tiger Universal):
http://support.apple.com/downloads/DL869/en_US/SecUpdSrvr2009-003Univ.dmg - Security Update 2009-003 (Server Tiger PPC):
http://support.apple.com/downloads/DL870/en_US/SecUpdSrvr2009-003PPC.dmg - Security Update 2009-003 (Tiger PPC):
http://support.apple.com/downloads/DL871/en_US/SecUpd2009-003PPC.dmg - Mac OS X Server 10.5.8 Update:
http://support.apple.com/downloads/DL867/en_US/MacOSXServerUpd10.5.8.dmg - Mac OS X Server 10.5.8 Combo Update:
http://support.apple.com/downloads/DL868/en_US/MacOSXServerUpdCombo10.5.8.dmg - Mac OS X 10.5.8 Update:
http://support.apple.com/downloads/DL865/en_US/MacOSXUpd10.5.8.dmg - Mac OS X 10.5.8 Combo Update:
http://support.apple.com/downloads/DL866/en_US/MacOSXUpdCombo10.5.8.dmg
Vulnerability Identifier
- CVE-2008-0674
- CVE-2008-1372
- CVE-2009-0040
- CVE-2009-0151
- CVE-2009-1235
- CVE-2009-1720
- CVE-2009-1721
- CVE-2009-1722
- CVE-2009-1723
- CVE-2009-1726
- CVE-2009-1727
- CVE-2009-1728
- CVE-2009-2188
- CVE-2009-2190
- CVE-2009-2191
- CVE-2009-2192
- CVE-2009-2193
- CVE-2009-2194
Source
Related Link
Share with