Apple Mac OS X Security Update 2006-003 Multiple Vulnerabilities
BID:17951
Info
Apple Mac OS X Security Update 2006-003 Multiple Vulnerabilities
| Bugtraq ID: | 17951 |
| Class: | Unknown |
| CVE: |
CVE-2006-1439 CVE-2006-1982 CVE-2006-1983 CVE-2006-1984 CVE-2006-1985 CVE-2006-1440 CVE-2006-1441 CVE-2006-1614 CVE-2006-1615 CVE-2006-1630 CVE-2006-1442 CVE-2006-1443 CVE-2006-1444 CVE-2006-1448 CVE-2006-1445 CVE-2006-0024 CVE-2005-2628 CVE-2006-1552 CVE-2006-1446 CVE-2006-1447 CVE-2005-4077 CVE-2006-1449 CVE-2006-1450 CVE-2006-1451 CVE-2006-1452 CVE-2006-1453 CVE-2006-1454 CVE-2006-1455 CVE-2006-1456 CVE-2005-2337 CVE-2006-1457 |
| Remote: | Yes |
| Local: | Yes |
| Published: | May 11 2006 12:00AM |
| Updated: | Mar 19 2008 02:40PM |
| Credit: | Various people are credited with the discovery of these issues, including: The vendor, Damien Bobillot, Brent Simmons of NewsGator Technologies, Inc., Tobias Hahn of HU Berlin, Ben Low of the University of New South Wales, Mike Price of McAfee AVERT Labs, |
| Vulnerable: |
Cosmicperl Directory Pro 10.0.3 Apple Safari 2.0.3 Apple Safari 2.0.2 Apple Safari 2.0.1 Apple Mobile Safari 0 Apple Mac OS X Server 10.5.2 Apple Mac OS X Server 10.5.1 Apple Mac OS X Server 10.4.11 Apple Mac OS X Server 10.4.10 Apple Mac OS X Server 10.4.9 Apple Mac OS X Server 10.4.8 Apple Mac OS X Server 10.4.7 Apple Mac OS X Server 10.4.6 Apple Mac OS X Server 10.4.5 Apple Mac OS X Server 10.4.4 Apple Mac OS X Server 10.4.3 Apple Mac OS X Server 10.4.2 Apple Mac OS X Server 10.4.1 Apple Mac OS X Server 10.4 Apple Mac OS X Server 10.3.9 Apple Mac OS X Server 10.3.8 Apple Mac OS X Server 10.3.7 Apple Mac OS X Server 10.3.6 Apple Mac OS X Server 10.3.5 Apple Mac OS X Server 10.3.4 Apple Mac OS X Server 10.3.3 Apple Mac OS X Server 10.3.2 Apple Mac OS X Server 10.3.1 Apple Mac OS X Server 10.3 Apple Mac OS X Server 10.2.8 Apple Mac OS X Server 10.2.7 Apple Mac OS X Server 10.2.6 Apple Mac OS X Server 10.2.5 Apple Mac OS X Server 10.2.4 Apple Mac OS X Server 10.2.3 Apple Mac OS X Server 10.2.2 Apple Mac OS X Server 10.2.1 Apple Mac OS X Server 10.2 Apple Mac OS X Server 10.1.5 Apple Mac OS X Server 10.1.4 Apple Mac OS X Server 10.1.3 Apple Mac OS X Server 10.1.2 Apple Mac OS X Server 10.1.1 Apple Mac OS X Server 10.1 Apple Mac OS X Server 10.0 Apple Mac OS X Server 10.5 Apple Mac OS X 10.5.2 Apple Mac OS X 10.5.1 Apple Mac OS X 10.4.11 Apple Mac OS X 10.4.10 Apple Mac OS X 10.4.9 Apple Mac OS X 10.4.8 Apple Mac OS X 10.4.7 Apple Mac OS X 10.4.6 Apple Mac OS X 10.4.5 Apple Mac OS X 10.4.4 Apple Mac OS X 10.4.3 Apple Mac OS X 10.4.2 Apple Mac OS X 10.4.1 Apple Mac OS X 10.4 Apple Mac OS X 10.3.9 Apple Mac OS X 10.3.8 Apple Mac OS X 10.3.7 Apple Mac OS X 10.3.6 Apple Mac OS X 10.3.5 Apple Mac OS X 10.3.4 Apple Mac OS X 10.3.3 Apple Mac OS X 10.3.2 Apple Mac OS X 10.3.1 Apple Mac OS X 10.3 Apple Mac OS X 10.2.8 Apple Mac OS X 10.2.7 Apple Mac OS X 10.2.6 Apple Mac OS X 10.2.5 Apple Mac OS X 10.2.4 Apple Mac OS X 10.2.3 Apple Mac OS X 10.2.2 Apple Mac OS X 10.2.1 Apple Mac OS X 10.2 Apple Mac OS X 10.1.5 Apple Mac OS X 10.1.4 Apple Mac OS X 10.1.3 Apple Mac OS X 10.1.2 Apple Mac OS X 10.1.1 Apple Mac OS X 10.1 Apple Mac OS X 10.1 Apple Mac OS X 10.0.4 Apple Mac OS X 10.0.3 Apple Mac OS X 10.0.2 Apple Mac OS X 10.0.1 Apple Mac OS X 10.0 3 Apple Mac OS X 10.0 Apple Mac OS X 10.5 |
| Not Vulnerable: | |
Discussion
Apple Mac OS X Security Update 2006-003 Multiple Vulnerabilities
Apple Mac OS X is reported prone to multiple security vulnerabilities.
These issue affect Mac OS X in the following applications or modules:
- AppKit
- ImageIO
- BOM
- CFNetwork
- ClamAV
- CoreFoundation
- CoreGraphics
- Finder
- FTPServer
- Flash Player
- ImageIO
- Keychain
- LaunchServices
- libcurl
- Mail
- MySQL Manager
- Preview
- QuickDraw
- QuickTime Streaming Server
- Ruby
- Safari
A remote attacker may exploit these issues to execute arbitrary code, trigger a denial-of-service condition, gain access to potentially sensitive information, or overwrite files. Other attacks may also be possible.
Apple Mac OS X 10.4.6 and prior are reported vulnerable to these issues.
Apple Mac OS X is reported prone to multiple security vulnerabilities.
These issue affect Mac OS X in the following applications or modules:
- AppKit
- ImageIO
- BOM
- CFNetwork
- ClamAV
- CoreFoundation
- CoreGraphics
- Finder
- FTPServer
- Flash Player
- ImageIO
- Keychain
- LaunchServices
- libcurl
- MySQL Manager
- Preview
- QuickDraw
- QuickTime Streaming Server
- Ruby
- Safari
A remote attacker may exploit these issues to execute arbitrary code, trigger a denial-of-service condition, gain access to potentially sensitive information, or overwrite files. Other attacks may also be possible.
Apple Mac OS X 10.4.6 and prior are reported vulnerable to these issues.
Exploit / POC
Apple Mac OS X Security Update 2006-003 Multiple Vulnerabilities
Some of these issues do not require exploits.
Some of these issues do not require exploits.
Solution / Fix
Apple Mac OS X Security Update 2006-003 Multiple Vulnerabilities
Solution:
Apple has released an advisory along with fixes to address these issues. Please see the referenced advisory for further information.
Apple Mac OS X Server 10.3.9
Apple Mac OS X 10.3.9
Apple Mac OS X 10.4.11
Apple Mac OS X Server 10.4.11
Apple Mac OS X Server 10.4.6
Apple Mac OS X 10.5.2
Apple Mac OS X Server 10.5.2
Solution:
Apple has released an advisory along with fixes to address these issues. Please see the referenced advisory for further information.
Apple Mac OS X Server 10.3.9
-
Apple SecUpdSrvr2006-003Pan.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=10488&cat= 1&platform=osx&method=sa/SecUpdSrvr2006-003Pan.dmg
Apple Mac OS X 10.3.9
-
Apple SecUpd2006-003Pan.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=10486&cat= 1&platform=osx&method=sa/SecUpd2006-003Pan.dmg
Apple Mac OS X 10.4.11
-
Apple SecUpd2008-002PPC.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=18157&cat= 57&platform=osx&method=sa/SecUpd2008-002PPC.dmg -
Apple SecUpd2008-002Univ.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=18157&cat= 57&platform=osx&method=sa/SecUpd2008-002Univ.dmg
Apple Mac OS X Server 10.4.11
-
Apple SecUpdSrvr2008-002PPC.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=18157&cat= 57&platform=osx&method=sa/SecUpdSrvr2008-002PPC.dmg -
Apple SecUpdSrvr2008-002Univ.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=18157&cat= 57&platform=osx&method=sa/SecUpdSrvr2008-002Univ.dmg
Apple Mac OS X Server 10.4.6
-
Apple SecUpdSrvr2006-003Ti.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=10487&cat= 1&platform=osx&method=sa/SecUpdSrvr2006-003Ti.dmg
Apple Mac OS X 10.5.2
-
Apple SecUpd2008-002.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=18157&cat= 57&platform=osx&method=sa/SecUpd2008-002.dmg
Apple Mac OS X Server 10.5.2
References
Apple Mac OS X Security Update 2006-003 Multiple Vulnerabilities
References:
References:
- About Security Update 2006-003 (Apple)
- Apple QuickTimeStreamingServer RTSP Server Vulnerability [MU-200605-02] (Mu Security)
- Apple Security Announce Archive (Apple)
- Apple Security Updates (Apple)
- Mac OS X Homepage (Apple)