Skip to main content

Apple Mac OS X Code Execution and Security Bypass Vulnerabilities

Last Update Date: 28 Jan 2011 Release Date: 7 Aug 2009 4814 Views

RISK: Medium Risk

Multiple vulnerabilities have been identified in Apple Mac OS X, which could be exploited by remote or local attackers to disclose sensitive information, bypass security restrictions, cause a denial of service or compromise an affected system. These issues are caused by out-of-bounds memory access issues, input validation errors, buffer overflows, uninitialized memory access issues, integer overflows, uninitialized pointers, implementation issues, format string errors, and logic and synchronization issues in bzip2, CFNetwork, ColorSync, CoreTypes, Dock, Image RAW, ImageIO, Kernel, launchd, Login Window, MobileMe, Networking, and XQuery.


Impact

  • Denial of Service
  • Remote Code Execution
  • Security Restriction Bypass
  • Information Disclosure

System / Technologies affected

  • Mac OS X version 10.4.11 and prior
  • Mac OS X Server version 10.4.11 and prior
  • Mac OS X versions 10.5 through 10.5.7
  • Mac OS X Server versions 10.5 through 10.5.7

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.


Vulnerability Identifier


Source


Related Link