Apple Mac OS X Multiple Vulnerabilities
Last Update Date:
15 Mar 2013 10:18
Release Date:
15 Mar 2013
4100
Views
RISK: High Risk
TYPE: Operating Systems - Mac OS
Multiple vulnerabilities have been identified in Mac OS X. A remote user can cause arbitrary code to be executed on the target user's system, and bypass authentication.
- A remote user may be able to bypass AppleID authentication when multiple users fail the AppleID certificate validation.
- A remote user can create a specially crafted Java Web Start application that, when loaded by the target user, will launch even if the Java plug-in was disabled.
- A remote user can send a specially crafted FaceTime:// URL that, when loaded by the target user, will bypass the standard confirmation prompt. Only version 10.8.x is affected.
- A remote user can create a specially crafted PDF file that, when loaded by the target user, will trigger a use-after-free in the handling of ink annotations and execute arbitrary code on the target system.
- A remote user with the ability to conduct a man-in-the-middle attack can insert plugin content into Software Update marketing text. Version 10.8.x is not affected.
- A remote user can create a specially crafted image file that, when loaded by the target user, will trigger a memory corruption error and execute arbitrary code on the target system. The code will run with the privileges of the target user. Version 10.8.x is affected.
Impact
- Remote Code Execution
- Security Restriction Bypass
System / Technologies affected
- Mac OS X 10.6.x, 10.7.x, 10.8.x
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- The vendor has issued a fix.
http://support.apple.com/kb/HT1222
Vulnerability Identifier
Source
Related Link
Share with