Apple Mac OS X Security Update 2005-006 Multiple Vulnerabilities

BID:13899

Info

Apple Mac OS X Security Update 2005-006 Multiple Vulnerabilities

Bugtraq ID: 13899
Class: Unknown
CVE: CVE-2005-1721
CVE-2005-1720
CVE-2005-1722
CVE-2005-1726
CVE-2005-1727
CVE-2005-1725
CVE-2005-1723
CVE-2005-1728
CVE-2005-1724
Remote: Yes
Local: Yes
Published: Jun 08 2005 12:00AM
Updated: Jul 12 2009 02:56PM
Credit: Discovery of the CoreGraphics issue is credited to Chris Evans. Discovery of the folder permissions issue is credited to Michael Haller. Discovery of the launchd issue is credited to Neil Archibald and Ilja Van Sprundel. Other issues were announced by t
Vulnerable: Apple Mac OS X Server 10.4.1
Apple Mac OS X Server 10.4
Apple Mac OS X Server 10.3.9
Apple Mac OS X 10.4.1
Apple Mac OS X 10.4
Apple Mac OS X 10.3.9
Not Vulnerable:

Discussion

Apple Mac OS X Security Update 2005-006 Multiple Vulnerabilities

Apple has released Security Update 2005-006 to address multiple local and remote Mac OS X vulnerabilities.

The following new vulnerabilities were addressed by the security update:

- A buffer overflow (CAN-2005-1721) in the AFP (Apple File Protocol) Server.

- A vulnerability (CAN-2005-1720) in AFP Server related to temporary ACLs.

- A denial of service vulnerability (CAN-2005-1722) in the CoreGraphics component.

- A local privilege escalation (CAN-2005-1726) in the CoreGraphics component.

- A local race condition vulnerability (CAN-2005-1727) related to permissions on the system cache and Dashboard folders.

- A local privilege escalation vulnerability (CAN-2005-1725) in the launch daemon (launchd).

- A vulnerability in Launch Services (CAN-2005-1723) could allow files to bypass "safe download" checks.

- A vulnerability (CAN-2005-1728) in the MCX Client that may allow local attackers to gain access to Portable Home Directory credentials.

- A vulnerability in NFS (CAN-2005-1724) could allow unauthorized access to exported filesystems.

These vulnerabilities will be separated into individual BIDs upon further analysis of the issues.

Exploit / POC

Apple Mac OS X Security Update 2005-006 Multiple Vulnerabilities

Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.

Solution / Fix

Apple Mac OS X Security Update 2005-006 Multiple Vulnerabilities

Solution:
Apple has released advisory APPLE-SA-2005-06-08 and fixes for these issues:


Apple Mac OS X 10.3.9

Apple Mac OS X Server 10.3.9

Apple Mac OS X Server 10.4.1

Apple Mac OS X 10.4.1

References

Apple Mac OS X Security Update 2005-006 Multiple Vulnerabilities

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report