Skip to main content

Apple Mac OS X Multiple Vulnerabilities

Last Update Date: 28 Jan 2011 Release Date: 4 Aug 2008 4792 Views

RISK: Medium Risk

Multiple vulnerabilities have been identified in Apple Mac OS X, which could be exploited by remote or local attackers to disclose sensitive information, bypass security restrictions, cause a denial of service or compromise an affected system.

1. Due to a stack buffer overflow error in CarbonCore when handling overly long filenames, which could be exploited to crash an affected application or execute arbitrary code.

2. Due to memory corruption errors in CoreGraphics when processing certain arguments, which could be exploited to crash an affected application (e.g .web browser) or execute arbitrary code.

3. Due to an integer overflow error in CoreGraphics when processing malformed PDF files, which could be exploited to crash an affected application or execute arbitrary code.

4. Due to a resource consumption in the Data Detectors Engine when handling textual content, which could be exploited to cause a denial of service.

5. Due to insecure permissions being set on "/usr/bin/emacs" by the "Repair Permissions" tool in Disk Utility, which could allow a local user to use emacs to run commands with system privileges.

6. Due to memory corruption errors in QuickLook when handling specially crafted MS Office files, which could be exploited by attackers to execute arbitrary code by tricking a user into downloading a malicious Office file.


Impact

  • Denial of Service
  • Remote Code Execution
  • Security Restriction Bypass
  • Information Disclosure

System / Technologies affected

  • Apple Mac OS X version 10.4.11 and prior
  • Apple Mac OS X version 10.5.4 and prior
  • Apple Mac OS X Server version 10.4.11 and prior
  • Apple Mac OS X Server version 10.5.4 and prior

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

Apple Security Update 2008-005 Server (PPC) :
http://www.apple.com/support/downloads/securityupdate2008005serverppc.html

Apple Security Update 2008-005 Server (Intel) :
http://www.apple.com/support/downloads/securityupdate2008005serverintel.html

Apple Security Update 2008-005 (PPC) :
http://www.apple.com/support/downloads/securityupdate2008005ppc.html

Apple Security Update 2008-005 (Intel) :
http://www.apple.com/support/downloads/securityupdate2008005intel.html

Apple Security Update 2008-005 (Leopard) :
http://www.apple.com/support/downloads/securityupdate2008005leopard.html


Vulnerability Identifier


Source


Related Link