Apple MacOS X ASN.1 Decoding Unspecified Remote Denial Of Service Vulnerability
BID:9266
Info
Apple MacOS X ASN.1 Decoding Unspecified Remote Denial Of Service Vulnerability
| Bugtraq ID: | 9266 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 20 2003 12:00AM |
| Updated: | Dec 20 2003 12:00AM |
| Credit: | The disclosure of this issue has been credited to the vendor. |
| Vulnerable: |
Apple Mac OS X Server 10.3.2 Apple Mac OS X Server 10.2.8 Apple Mac OS X 10.3.2 Apple Mac OS X 10.2.8 |
| Not Vulnerable: | |
Discussion
Apple MacOS X ASN.1 Decoding Unspecified Remote Denial Of Service Vulnerability
It has been reported that Apple MacOS X may be prone to a remote denial of service vulnerability due to improper handling of ASN.1 sequences for the Public Key Infrastructure (PKI). This could potentially lead to an attacker crashing a service that uses an implementation of the vulnerable software. This issue is reported to be similar to OpenSSL ASN.1 Large Recursion Remote Denial Of Service Vulnerability described in BID 8970.
Due to a lack of details further information concerning this issue cannot be provided at the moment. This BID will be updated as more information becomes available
It has been reported that Apple MacOS X may be prone to a remote denial of service vulnerability due to improper handling of ASN.1 sequences for the Public Key Infrastructure (PKI). This could potentially lead to an attacker crashing a service that uses an implementation of the vulnerable software. This issue is reported to be similar to OpenSSL ASN.1 Large Recursion Remote Denial Of Service Vulnerability described in BID 8970.
Due to a lack of details further information concerning this issue cannot be provided at the moment. This BID will be updated as more information becomes available
Exploit / POC
Apple MacOS X ASN.1 Decoding Unspecified Remote Denial Of Service Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Apple MacOS X ASN.1 Decoding Unspecified Remote Denial Of Service Vulnerability
Solution:
Apple has released advisories to fix this issue in Apple Jaguar for Mac OS X 10.2.8 and Mac OS X Server 10.2.8 and Panther for Mac OS X 10.3.2 and Mac OS X Server 10.3.2. Please see referenced advisories for more details about obtaining fixes.
Solution:
Apple has released advisories to fix this issue in Apple Jaguar for Mac OS X 10.2.8 and Mac OS X Server 10.2.8 and Panther for Mac OS X 10.3.2 and Mac OS X Server 10.3.2. Please see referenced advisories for more details about obtaining fixes.
References
Apple MacOS X ASN.1 Decoding Unspecified Remote Denial Of Service Vulnerability
References:
References: