Multiple vulnerabilities have been identified in Apple Mac OS X, which could be exploited by remote or local attackers to execute arbitrary commands, cause a denial of service, disclose sensitive information, or bypass security restrictions.
These issues are due to errors in ColorSync, CoreGraphics, Crash Reporter, CUPS, Disk Images, DS Plug-Ins, Flash Player, GNU Tar, HFS, HID Family, ImageIO, Kernel, MySQL Server, Networking, OpenSSH, Printing, QuickDraw Manager, servermgrd, SMB File Server, Software Update, sudo and WebLog.
For additional information, see : FrSIRT/ADV-2007-0074 - FrSIRT/ADV-2006-4629 - FrSIRT/ADV-2007-0141 - FrSIRT/ADV-2007-0171 - FrSIRT/ADV-2006-4448 - FrSIRT/ADV-2006-4714 - FrSIRT/ADV-2006-4762 - FrSIRT/ADV-2006-4746 - FrSIRT/ADV-2007-0191 - FrSIRT/ADV-2007-0337 - FrSIRT/ADV-2006-4094 - FrSIRT/ADV-2006-0684 - FrSIRT/ADV-2006-4717 - FrSIRT/ADV-2006-1633 - FrSIRT/ADV-2006-2105 - FrSIRT/ADV-2006-3079 - FrSIRT/ADV-2006-3306 - FrSIRT/ADV-2006-0306 - FrSIRT/ADV-2006-3777 - FrSIRT/ADV-2006-3633
Credits
Vulnerabilities reported by Tom Ferris, Andrew Garber (University of Victoria), Alex Harper, Michael Evans, Luke Church (Computer Laboratory - University of Cambridge), Ilja van Sprundel, Jeff Mccune (Ohio State University), Mike Price (McAfee AVERT Labs), Cameron Kay (Massey University), and Kevin Finisterre (DigitalMunition).
ChangeLog
2007-03-13 : Initial release
Vulnerability Management
Subscribe to FrSIRT VNS and receive real-time e-mail and SMS alerts when new vulnerabilities, exploits, or patches relevant to your systems and network configurations are available.
Feedback
If you have additional information or corrections for this security advisory please submit them via our contact form or by email to updates@frsirt.com.