Apple Mac OS X Multiple Security Vulnerabilities
BID:11322
Info
Apple Mac OS X Multiple Security Vulnerabilities
| Bugtraq ID: | 11322 |
| Class: | Unknown |
| CVE: |
CVE-2004-0921 CVE-2004-0922 CVE-2004-0924 CVE-2004-0926 CVE-2004-0927 |
| Remote: | Yes |
| Local: | Yes |
| Published: | Oct 04 2004 12:00AM |
| Updated: | Jul 12 2009 07:06AM |
| Credit: | The vendor announced these vulnerabilities. |
| Vulnerable: |
Apple QuickTime Player 6.5.1 Apple QuickTime Player 6.5 Apple QuickTime Player 6.1 Apple QuickTime Player 5.0.2 Apple QuickTime Player 6 Apple Mac OS X Server 10.3.5 Apple Mac OS X Server 10.3.4 Apple Mac OS X Server 10.3.3 Apple Mac OS X Server 10.3.2 Apple Mac OS X Server 10.3.1 Apple Mac OS X Server 10.3 Apple Mac OS X Server 10.2.8 Apple Mac OS X Server 10.2.7 Apple Mac OS X Server 10.2.6 Apple Mac OS X Server 10.2.5 Apple Mac OS X Server 10.2.4 Apple Mac OS X Server 10.2.3 Apple Mac OS X Server 10.2.2 Apple Mac OS X Server 10.2.1 Apple Mac OS X Server 10.2 Apple Mac OS X 10.3.5 Apple Mac OS X 10.3.4 Apple Mac OS X 10.3.3 Apple Mac OS X 10.3.2 Apple Mac OS X 10.3.1 Apple Mac OS X 10.3 Apple Mac OS X 10.2.8 Apple Mac OS X 10.2.7 Apple Mac OS X 10.2.6 Apple Mac OS X 10.2.5 Apple Mac OS X 10.2.4 Apple Mac OS X 10.2.3 Apple Mac OS X 10.2.2 Apple Mac OS X 10.2.1 Apple Mac OS X 10.2 |
| Not Vulnerable: |
Apple QuickTime Player 6.5.2 |
Discussion
Apple Mac OS X Multiple Security Vulnerabilities
Multiple security vulnerabilities are reported in Mac OS X. A security update is available to address these issues and to provide other enhancements. The following issues are reported:
Apple AFP server is reported prone to a remote denial of service vulnerability.
A weak permissions vulnerability is reported to affect the AFP server. This may result in a false sense of security for an administrator.
A vulnerability is reported to exist in the NetInfoManager utility. It is reported that the utility will, under certain circumstances, report the status of certain accounts as disabled when they are not.
A heap-based buffer overrun is reported to exist in the QuickTime utility. An attacker may exploit this vulnerability to execute arbitrary instructions in the context of the user that is running the vulnerable software.
Finally, ServerAdmin is reported prone to a weak default configuration vulnerability. This may result in ServerAdmin traffic being intercepted and decrypted by a remote attacker. This vulnerability has been split into BID 11344.
Some of these issues may already be described in previous BIDs. This BID will be split up into unique BIDs when further analysis of this update is complete.
Multiple security vulnerabilities are reported in Mac OS X. A security update is available to address these issues and to provide other enhancements. The following issues are reported:
Apple AFP server is reported prone to a remote denial of service vulnerability.
A weak permissions vulnerability is reported to affect the AFP server. This may result in a false sense of security for an administrator.
A vulnerability is reported to exist in the NetInfoManager utility. It is reported that the utility will, under certain circumstances, report the status of certain accounts as disabled when they are not.
A heap-based buffer overrun is reported to exist in the QuickTime utility. An attacker may exploit this vulnerability to execute arbitrary instructions in the context of the user that is running the vulnerable software.
Finally, ServerAdmin is reported prone to a weak default configuration vulnerability. This may result in ServerAdmin traffic being intercepted and decrypted by a remote attacker. This vulnerability has been split into BID 11344.
Some of these issues may already be described in previous BIDs. This BID will be split up into unique BIDs when further analysis of this update is complete.
Exploit / POC
Apple Mac OS X Multiple Security Vulnerabilities
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Apple Mac OS X Multiple Security Vulnerabilities
Solution:
Apple has released updates for this issue that may be applied through Software Update. Manual updates are also available.
Apple has released security advisory APPLE-SA-2004-10-27 along with an upgrade dealing with the QuickTime issue reported in this vulnerability. The previous security updates deals with this issue only for the Apple Mac OS X platform. For more information, please see the referenced advisory.
Apple QuickTime Player 6
Apple Mac OS X 10.2.8
Apple Mac OS X Server 10.2.8
Apple Mac OS X Server 10.3.5
Apple Mac OS X 10.3.5
Apple QuickTime Player 5.0.2
Apple QuickTime Player 6.1
Apple QuickTime Player 6.5
Apple QuickTime Player 6.5.1
Solution:
Apple has released updates for this issue that may be applied through Software Update. Manual updates are also available.
Apple has released security advisory APPLE-SA-2004-10-27 along with an upgrade dealing with the QuickTime issue reported in this vulnerability. The previous security updates deals with this issue only for the Apple Mac OS X platform. For more information, please see the referenced advisory.
Apple QuickTime Player 6
-
Apple QuickTime 6.5.2
http://www.apple.com/quicktime/download/standalone/
Apple Mac OS X 10.2.8
-
Apple Security Update 2004-09-30 (Mac OS X 10.2.8 Client and Server)
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=04829&plat form=osx&method=sa/SecUpd2004-09-30Jag.dmg
Apple Mac OS X Server 10.2.8
-
Apple Security Update 2004-09-30 (Mac OS X 10.2.8 Client and Server)
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=04829&plat form=osx&method=sa/SecUpd2004-09-30Jag.dmg
Apple Mac OS X Server 10.3.5
-
Apple Security Update 2004-09-30 (Mac OS X 10.3.5 Client & Server)
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=04830&plat form=osx&method=sa/SecUpd2004-09-30Pan.dmg
Apple Mac OS X 10.3.5
-
Apple Security Update 2004-09-30 (Mac OS X 10.3.5 Client & Server)
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=04830&plat form=osx&method=sa/SecUpd2004-09-30Pan.dmg
Apple QuickTime Player 5.0.2
-
Apple QuickTime 6.5.2
http://www.apple.com/quicktime/download/standalone/
Apple QuickTime Player 6.1
-
Apple QuickTime 6.5.2
http://www.apple.com/quicktime/download/standalone/
Apple QuickTime Player 6.5
-
Apple QuickTime 6.5.2
http://www.apple.com/quicktime/download/standalone/
Apple QuickTime Player 6.5.1
-
Apple QuickTime 6.5.2
http://www.apple.com/quicktime/download/standalone/
References
Apple Mac OS X Multiple Security Vulnerabilities
References:
References: