About Us | Contact Us

 


 

VUPEN Free Resources

 
  VUPEN Security Advisories
 
  VUPEN Security Blog & News
  Zero-day Attacks Monitor
  Daily Security Mailinglist
  Explanation of Terms
  Advanced Search Engine
 
   

Apple Mac OS X Code Execution and Security Bypass Vulnerabilities

VUPEN ID VUPEN/ADV-2010-0173
CVE ID CVE-2009-2285 - CVE-2009-3553 - CVE-2009-3555 - CVE-2009-3794 - CVE-2009-3796 - CVE-2009-3797 - CVE-2009-3798 - CVE-2009-3799 - CVE-2009-3800 - CVE-2009-3951 - CVE-2010-0036 - CVE-2010-0037
 
CWE ID Available in VUPEN VNS Customer Area
CVSS V2 Available in VUPEN VNS Customer Area
Rated as Critical 
Impact Available in VUPEN VNS Customer Area
Authentication Level Available in VUPEN VNS Customer Area
Access Vector Available in VUPEN VNS Customer Area
Release Date 2010-01-20
Share Twitter LinkedIn Facebook Delicious Digg Slashdot

Technical Description

Multiple vulnerabilities have been identified in Apple Mac OS X, which could be exploited by remote or local attackers to disclose sensitive information, bypass security restrictions, cause a denial of service or compromise an affected system. These issues are caused by errors in CoreAudio, CUPS, Flash Player plug-in, ImageIO, Image RAW, and OpenSSL. For additional information, see : VUPEN/ADV-2009-1637 - VUPEN/ADV-2009-3164 - VUPEN/ADV-2009-3278 - VUPEN/ADV-2009-3456

Affected Products

Apple Mac OS X version 10.6.2 and prior
Apple Mac OS X version 10.5.8 and prior
Apple Mac OS X Server version 10.6.2 and prior
Apple Mac OS X Server version 10.5.8 and prior

Solution 

Apply Security Update 2010-001 Client (Leopard) :
http://support.apple.com/kb/DL993

Apply Security Update 2010-001 Server (Leopard) :
http://support.apple.com/kb/DL992

Apply Security Update 2010-001 (Snow Leopard) :
http://support.apple.com/kb/DL994

References

http://www.vupen.com/english/advisories/2010/0173
http://support.apple.com/kb/HT4004

Credits 

Vulnerabilities reported by Tobias Klein (trapkit.de), Damian Put via ZDI, Bing Liu (Fortinet FortiGuard Global Security Research Team), Will Dormann (CERT), Manuel Caballero, Microsoft Vulnerability Research, Jason Carr (Carnegie Mellon University Computing Services), and Dispensa and Marsh Ray (PhoneFactor, Inc).

Changelog 

2010-01-20 : Initial release

Feedback 

If you have additional information or corrections for this security advisory please submit them via our contact form.

 

Monthly Statistics 

 

 VUPEN Security Advisories By Criticality: Sep 2010


  Critical Risk

: 14%

  High Risk
: 3%

  Moderate Risk
: 45%

  Low Risk
: 38%

Get a real-time view of the vulnerabilities affecting your systems using the VUPEN VNS reporting capabilities.
 

 

Try VUPEN VNS 

 

 





© 2004-2010 VUPEN Security - Copyright - Privacy Policy