Apple Mac OS X Multiple Java Vulnerabilities
RISK: Medium Risk
Multiple vulnerabilities have been identified in Apple Mac OS X, which could be exploited by remote attackers or malicious users to execute arbitrary code.
1. Amemory corruption error in Java's handling of applet window bounds, which could allow remote attackers to compromise a vulnerable system via a specially crafted web page.
2. An input validation error in Java updateSharingD when handling of Mach RPC messages, which could allow a local attacker to execute arbitrary code with the privileges of another user who runs a malicious Java application.
Other vulnerabilities have also been addressed in Oracle Sun Java. For additional information, see : Oracle Sun Java JDK / JRE / SDK Multiple Vulnerabilities
Impact
- Remote Code Execution
System / Technologies affected
- Apple Mac OS X version 10.6.4 and prior
- Apple Mac OS X version 10.5.8 and prior
- Apple Mac OS X Server version 10.6.4 and prior
- Apple Mac OS X Server version 10.5.8 and prior
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
Java for Mac OS X 10.6 Update 3 :
http://support.apple.com/kb/DL972Java for Mac OS X 10.5 Update 8 :
http://support.apple.com/kb/DL971
Vulnerability Identifier
Source
Related Link
Share with