Apple Mac OS X Keychain Security Bypass Vulnerability
BID:26877
Info
Apple Mac OS X Keychain Security Bypass Vulnerability
| Bugtraq ID: | 26877 |
| Class: | Access Validation Error |
| CVE: |
CVE-2007-5862 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 14 2007 12:00AM |
| Updated: | Dec 17 2007 10:01PM |
| Credit: | Bruno Harbulot of the University of Manchester is credited with discovering this issue. |
| Vulnerable: |
Apple Mac OS X Server 10.4.11 Apple Mac OS X Server 10.4.10 Apple Mac OS X 10.4.11 Apple Mac OS X 10.4.10 |
| Not Vulnerable: |
Apple Mac OS X Server 10.5.1 Apple Mac OS X Server 10.5 Apple Mac OS X 10.5.1 Apple Mac OS X 10.5 |
Discussion
Apple Mac OS X Keychain Security Bypass Vulnerability
Apple Mac OS X Keychain is prone to a security-bypass vulnerability because it fails to properly validate user credentials before performing certain actions.
This issue may stem from a security issue in Java.
A successful attack allows unauthorized users to modify other users' accounts, which may aid in further attacks.
This issue affects Mac OS X 10.4.10 and Mac OS X Server 10.4.10.
Apple Mac OS X Keychain is prone to a security-bypass vulnerability because it fails to properly validate user credentials before performing certain actions.
This issue may stem from a security issue in Java.
A successful attack allows unauthorized users to modify other users' accounts, which may aid in further attacks.
This issue affects Mac OS X 10.4.10 and Mac OS X Server 10.4.10.
Exploit / POC
Apple Mac OS X Keychain Security Bypass Vulnerability
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
Solution / Fix
Apple Mac OS X Keychain Security Bypass Vulnerability
Solution:
Apple has released Java Release 6 to address this issue. Please see the references for more information.
Apple Mac OS X Server 10.4.10
Apple Mac OS X 10.4.10
Apple Mac OS X Server 10.4.11
Apple Mac OS X 10.4.11
Solution:
Apple has released Java Release 6 to address this issue. Please see the references for more information.
Apple Mac OS X Server 10.4.10
-
Apple Java for Mac OS X 10.4, Release 6
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=16540&cat= 1&platform=osx&method=sa/JavaForMacOSX10.4Release6.dmg
Apple Mac OS X 10.4.10
-
Apple Java for Mac OS X 10.4, Release 6
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=16540&cat= 1&platform=osx&method=sa/JavaForMacOSX10.4Release6.dmg
Apple Mac OS X Server 10.4.11
-
Apple Java for Mac OS X 10.4, Release 6
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=16540&cat= 1&platform=osx&method=sa/JavaForMacOSX10.4Release6.dmg
Apple Mac OS X 10.4.11
-
Apple Java for Mac OS X 10.4, Release 6
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=16540&cat= 1&platform=osx&method=sa/JavaForMacOSX10.4Release6.dmg
References
Apple Mac OS X Keychain Security Bypass Vulnerability
References:
References:
- CVE Request: python-rsa signature forgery (Filippo Valsorda )
- Cisco TelePresence Video Communication Server (VCS) Homepage (Cisco)