French Security Incident Response Team

FrSIRT   

      

   français French  anglais English

 
Vulnerability Notification Service
FrSIRT Partner Program
14-Day Free Trial
Contact FrSIRT Sales Dept.
 

Security Advisories
Linux Security Advisories
Virus and Threats Advisories
Latest Security News
Latest Zero Day Threats
Advisories and vulnerabilities by Vendor
Advisories and vulnerabilities by Keyword
 

Report a security incident
Report a new vulnerability
Security Mailinglist
 

Our Company
FrSIRT in the News
Advertise on FrSIRT.COM
Security Researchers and Exploit Writers Jobs
Contact Us

Apple Mac OS X Code Execution and Security Bypass Vulnerabilities


Title : Apple Mac OS X Code Execution and Security Bypass Vulnerabilities
Advisory ID : FrSIRT/ADV-2008-0495
CVE ID : CVE-2007-4568 - CVE-2007-6015 - CVE-2008-0035 - CVE-2008-0037 - CVE-2008-0038 - CVE-2008-0039 - CVE-2008-0040 - CVE-2008-0041 - CVE-2008-0042
Rated as : Critical 
Remotely Exploitable : Yes
Locally Exploitable : Yes
Release Date : 2008-02-12

Advisory Details

 
  Description
  Affected Products
  Solution
  References
Technical Description    Receive FrSIRT alerts in a Text format  Receive FrSIRT alerts in a PDF format  Receive FrSIRT alerts in an XML format  Receive FrSIRT notifications by SMS 

Multiple vulnerabilities have been identified in Apple Mac OS X, which could be exploited by remote or local attackers to cause a denial of service, disclose sensitive information, bypass security restrictions or compromise an affected system.

The first issue is caused by a memory corruption error in Safari when handling malformed URLs, which could be exploited by attackers to crash a vulnerable browser or execute arbitrary code.

The second weakness is caused by a design error in Launch Services, which could allow an uninstalled application to be launched if it is present in a Time Machine backup.

The third vulnerability is caused by an implementation issue in Mail's handling of "file://" URLs, which could allow arbitrary applications to be launched without warning when a user clicks a URL in a message.

The fourth issue is caused by a memory corruption error in NFS's handling of mbuf chains, which could be exploited by attackers to crash or compromise an affected system.

The fifth weakness is caused by an error in Parental Controls that inadvertently contact www.apple.com when a website is unblocked, which could allow a remote user to detect the machines running Parental Controls.

The sixth issue is caused by an error in Samba. For additional information, see : FrSIRT/ADV-2007-4153

The seventh vulnerability is caused by an input validation error in the processing of URL schemes handled by Terminal.app, which could be exploited by a malicious web site to cause an application to be launched with controlled command line arguments, which may lead to arbitrary code execution.

The eighth issue is caused by errors in X11. For additional information, see : FrSIRT/ADV-2007-3337

The ninth vulnerability is caused by an error in the X11 server that does not correctly read its "Allow connections from network client" preference, which can cause the X11 server to allow connections from network clients, even when the preference is turned off.

Credits

Vulnerabilities reported by Kevin Finisterre (Netragard), Steven Fisher (Discovery Software), Ian Coutier, Oleg Drokin (Sun Microsystems), Jesse Pearson, Alin Rad Pop (Secunia Research), Olli Leppanen (Digital Film Finland) and Brian Mastenbrook.

ChangeLog

2008-02-12 : Initial release

Vulnerability Management

Subscribe to FrSIRT VNS and receive real-time e-mail and SMS alerts when new vulnerabilities, exploits, or patches relevant to your systems and network configurations are available.

Feedback

If you have additional information or corrections for this security advisory please submit them via our contact form or by email to updates@frsirt.com.


 
 

Search

      

Mailinglist

    
 

Microsoft Internet Explorer Frame Cross-Domain Scripting Vulnerability

Microsoft Internet Explorer "location" Cross-Domain Scripting Issue

Microsoft Windows PGM Remote Denial of Service Vulnerability (MS08-036)

Microsoft Active Directory Remote Denial of Service (MS08-035)

Microsoft Windows WINS Local Privilege Escalation Vulnerability (MS08-034)

Microsoft Windows DirectX Remote Code Execution (MS08-033)

Microsoft Windows Speech API Remote Code Execution (MS08-032)

Mozilla Products Remote Code Execution and Security Bypass Issues

Mozilla Firefox Unspecified Remote Command Execution Vulnerability

Mozilla JavaScript Garbage Collector Code Execution Vulnerability

Mozilla Thunderbird Code Execution and Cross Site Scripting Issues

Mozilla Firefox and SeaMonkey Multiple Remote Code Execution Issues

Mozilla Thunderbird Multiple Security Bypass and Code Execution Issues

Mozilla Firefox and SeaMonkey Multiple Remote Code Execution Issues

IBM Tivoli Directory Server Entry Handling Double-Free Vulnerability

IBM AFP Viewer Plug-In "SRC" Property Buffer Overflow Vulnerability

IBM Hardware Management Console Cross Site Scripting Vulnerabilities

IBM OS/400 BrSmRcvAndCheck Local Buffer Overflow Vulnerability

IBM DB2 Multiple Buffer Overflow and Security Bypass Vulnerabilities

IBM WebSphere Application Server Security Exposure Vulnerability

IBM AIX Multiple Command Local Privilege Escalation Vulnerabilities

Copyright 2003-2008 © FrSIRT.COM - Privacy Policy