Multiple vulnerabilities have been identified in Apple Mac OS X, which could be exploited by remote or local attackers to execute arbitrary commands, cause a denial of service, disclose sensitive information, or bypass security restrictions.
These issues are due to errors in ColorSync, CoreGraphics, Crash Reporter, CUPS, Disk Images, DS Plug-Ins, Flash Player, GNU Tar, HFS, HID Family, ImageIO, Kernel, MySQL Server, Networking, OpenSSH, Printing, QuickDraw Manager, servermgrd, SMB File Server, Software Update, sudo and WebLog.
For additional information, see : VUPEN/ADV-2007-0074 - VUPEN/ADV-2006-4629 - VUPEN/ADV-2007-0141 - VUPEN/ADV-2007-0171 - VUPEN/ADV-2006-4448 - VUPEN/ADV-2006-4714 - VUPEN/ADV-2006-4762 - VUPEN/ADV-2006-4746 - VUPEN/ADV-2007-0191 - VUPEN/ADV-2007-0337 - VUPEN/ADV-2006-4094 - VUPEN/ADV-2006-0684 - VUPEN/ADV-2006-4717 - VUPEN/ADV-2006-1633 - VUPEN/ADV-2006-2105 - VUPEN/ADV-2006-3079 - VUPEN/ADV-2006-3306 - VUPEN/ADV-2006-0306 - VUPEN/ADV-2006-3777 - VUPEN/ADV-2006-3633
Affected Products
Apple Mac OS X version 10.3.9 and prior
Apple Mac OS X Server version 10.3.9 and prior
Apple Mac OS X version 10.4.8 and prior
Apple Mac OS X Server version 10.4.8 and prior
Solution
Apply updates :
http://www.apple.com/support/downloads/
References
http://www.vupen.com/english/advisories/2007/0930
http://docs.info.apple.com/article.html?artnum=305214
Credits
Vulnerabilities reported by Tom Ferris, Andrew Garber (University of Victoria), Alex Harper, Michael Evans, Luke Church (Computer Laboratory - University of Cambridge), Ilja van Sprundel, Jeff Mccune (Ohio State University), Mike Price (McAfee AVERT Labs), Cameron Kay (Massey University), and Kevin Finisterre (DigitalMunition).
ChangeLog
2007-03-13 : Initial release
Vulnerability Management
Subscribe to VUPEN VNS and receive real-time alerts when new advisories or patches relevant to your systems and network configurations are available.
Feedback
If you have additional information or corrections for this security advisory please submit them via our contact form.