Apple Mac OS X Prior to 10.10.2 Multiple Security Vulnerabilities
BID:72328
Info
Apple Mac OS X Prior to 10.10.2 Multiple Security Vulnerabilities
| Bugtraq ID: | 72328 |
| Class: | Unknown |
| CVE: |
CVE-2014-8820 CVE-2014-8826 CVE-2014-8827 CVE-2014-8838 CVE-2014-8839 CVE-2014-8822 CVE-2014-8830 CVE-2014-4499 CVE-2014-8832 CVE-2014-8833 CVE-2014-8831 CVE-2014-8836 CVE-2014-8837 CVE-2014-8834 CVE-2014-8835 CVE-2014-8819 CVE-2014-8816 CVE-2014-4497 CVE-2014-8828 CVE-2014-8829 CVE-2014-4498 CVE-2014-8823 CVE-2014-8821 CVE-2014-8824 CVE-2014-8825 CVE-2014-8817 |
| Remote: | Yes |
| Local: | Yes |
| Published: | Jan 27 2015 12:00AM |
| Updated: | Apr 12 2019 06:00PM |
| Credit: | Ian Beer of Google Project Zero, Roberto Paleari and Aristide Fattori of Emaze Networks, Trammell Hudson of Two Sigma Investments, Sten Petersen, Mike Myers, of Digital Operatives LLC, Vitaliy Toropov working with HP's Zero Day Initiative, @PanguTeam, Alex |
| Vulnerable: |
Apple Mac OS X 10.10 Apple Mac OS X 10.9.5 Apple Mac OS X 10.8.5 Apple Mac OS X 10.10.1 |
| Not Vulnerable: |
Apple Mac Os X 10.10.3 Apple Mac OS X 10.10.2 |
Discussion
Apple Mac OS X Prior to 10.10.2 Multiple Security Vulnerabilities
Apple Mac OS X is prone to multiple security vulnerabilities.
The update addresses new vulnerabilities that affect Bluetooth, CPU Software, CommerceKit Framework, CoreGraphics, CoreSymbolication, Intel Graphics Driver, IOHIDFamily, IOUSBFamily, Kernel, LaunchServices, LoginWindow, Sandbox, SceneKit, security, security_taskgate, Spotlight, SpotlightIndex, sysmond, and UserAccountUpdater components.
Attackers can exploit these issues to execute arbitrary code, gain unauthorized access, bypass security restrictions, disclose sensitive information and perform other attacks. Failed attacks may cause denial-of-service conditions.
These issues affect OS X prior to 10.10.2.
Apple Mac OS X is prone to multiple security vulnerabilities.
The update addresses new vulnerabilities that affect Bluetooth, CPU Software, CommerceKit Framework, CoreGraphics, CoreSymbolication, Intel Graphics Driver, IOHIDFamily, IOUSBFamily, Kernel, LaunchServices, LoginWindow, Sandbox, SceneKit, security, security_taskgate, Spotlight, SpotlightIndex, sysmond, and UserAccountUpdater components.
Attackers can exploit these issues to execute arbitrary code, gain unauthorized access, bypass security restrictions, disclose sensitive information and perform other attacks. Failed attacks may cause denial-of-service conditions.
These issues affect OS X prior to 10.10.2.
Exploit / POC
Apple Mac OS X Prior to 10.10.2 Multiple Security Vulnerabilities
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Note: Some of these issues will not require specific exploit code and may be trivial to exploit.
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Note: Some of these issues will not require specific exploit code and may be trivial to exploit.
Solution / Fix
Apple Mac OS X Prior to 10.10.2 Multiple Security Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Apple Mac OS X Prior to 10.10.2 Multiple Security Vulnerabilities
References:
References: