Vendor Status Note JVNCIAC-O-212
|
MacOS X に複数の脆弱性
|
概要
|
Apple MacOS X には、バッファオーバーフローをはじめとする複数の脆弱性があります。
影響を受けるシステム
- Mac OS X 10.3.4
- Mac OS X 10.3.5
- Mac OS X Server 10.3.4
- Mac OS X Server 10.3.5
- Mac OS X 10.2.8
- Mac OS X Server 10.2.8
|
想定される影響
|
サービス運用妨害 (DoS) 攻撃、遠隔からの第三者によるユーザ権限取得、ローカルユーザによる root 権限取得などの影響を受ける可能性があります。
|
ベンダ情報
|
|
参考情報
|
- ISS X-Force Database: libpng-file-offset-bo(10925)
libpng file offset buffer overflow
- ISS X-Force Database: openssh-scp-file-overwrite(16323)
OpenSSH scp file overwrite
- ISS X-Force Database: tcpdump-isakmp-delete-bo(15680)
tcpdump ISAKMP packet delete payload buffer overflow
- ISS X-Force Database: tcpdump-isakmp-integer-underflow(15679)
tcpdump ISAKMP packet integer underflow
- ISS X-Force Database: safari-array-dos(15413)
Safari Web browser application large array denial of service
- ISS X-Force Database: libpng-png-dos(16022)
libpng PNG image denial of service
- ISS X-Force Database: rsync-write-files(16014)
Linux rsync allows files to be written outside a module's path
- ISS X-Force Database: apache-modssl-uuencode-bo(16214)
Apache mod_ssl ssl_util_uuencode_binary buffer overflow
- ISS X-Force Database: apache-apgetmimeheaderscore-dos(16524)
Apache HTTP Server ap_get_mime_headers_core denial of service
- ISS X-Force Database: squirrelmail-sql-injection(16235)
SquirrelMail unspecified SQL injection
- ISS X-Force Database: kerberos-krb5anametolocalname-bo(16268)
Kerberos krb5_aname_to_localname library function buffer overflow
- ISS X-Force Database: libpng-pnghandle-bo(16894)
libpng png_handle_sBIT and png_handle_tRNS buffer overflow
- ISS X-Force Database: libpng-pnghandleiccp-dos(16895)
libpng png_handle_iCCP denial of service
- ISS X-Force Database: lilbpng-integer-bo(16896)
libpng integer buffer overflow
- ISS X-Force Database: racoon-eaycheckx509cert-auth-bypass(16414)
Racoon and IPsec-Tools eay_check_x509cert authentication bypass
- ISS X-Force Database: http-frame-spoof(1598)
Web browser frame spoof
- ISS X-Force Database: safari-web-info-disclosure(16944)
Safari Web POST data information disclosure
- ISS X-Force Database: macos-tcp-ip-dos(16946)
Mac OS TCP/IP denial of service
- ISS X-Force Database: tnftpd-gain-access(17020)
tnftpd allows attacker to gain root access
- ISS X-Force Database: macos-corefoundation-gain-privileges(17291)
Mac OS X CoreFoundation allows elevated privileges
- ISS X-Force Database: macos-corefoundation-bo(17295)
Mac OS X CoreFoundation buffer overflow
- ISS X-Force Database: openldap-crypt-gain-access(17300)
OpenLDAP CRYPT password gain access
|
|
Copyright(C) 2002-2009 Keio Univ. All rights reserved.
|