Apple Mac OS X Multiple Vulnerabilities
Last Update Date:
6 Jun 2013 18:55
Release Date:
6 Jun 2013
3984
Views
RISK: High Risk
TYPE: Operating Systems - Mac OS
Multiple vulnerabilities have been identified in Apple OS X. A remote user can execute arbitrary code on the target system. A remote authenticated user can write files outside of the target SMB directory. A local user can bypass security restrictions.
- A local user with access to a target user's session can log into previously accessed sites, even if Private Browsing had been used.
- A remote user can create a specially crafted URL that, when loaded by the target user, will trigger a stack allocation error in the handling of text glyphs and execute arbitrary code on the target system.
- A remote user can create a specially crafted movie file that, when loaded by the target user, will trigger an uninitialized memory access error and execute arbitrary code on the target system.
- A remote user can send a specially crafted message to trigger a flaw in Directory Service and execute arbitrary code.
- A local non-administrative user can disable FileVault.
- A remote user can create a specially crafted PICT file that, when loaded by the target user, will trigger a buffer overflow in QuickDraw Manager and execute arbitrary code on the target system.
- A remote authenticated user can write to files located outside of the SMB share.
Impact
- Cross-Site Scripting
- Denial of Service
- Remote Code Execution
- Information Disclosure
- Data Manipulation
System / Technologies affected
- 10.8.x prior to 10.8.4; 10.6.x, 10.7.x
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- The vendor has issued a fix (10.8.4; Security Update 2013-002).
http://support.apple.com/kb/HT5784
Vulnerability Identifier
Source
Related Link
Share with