Beschreibung: | Summary: Apple Mac OS X is prone to multiple vulnerabilities.
Vulnerability Insight: Multiple flaws exist due to:
- The Wiki Server does not specify an explicit character set when serving HTML documents in response to user requests.
- Multiple errors in SquirrelMail.
- A configuration issue exists in Apple's distribution of Samba, the server used for SMB file sharing.
- An input validation error in the Ruby WEBrick HTTP server's handling of error pages.
- A buffer overflow exists in libcurl's handling of gzip-compressed web content.
- An integer overflow exists in AES and RC4 decryption operations of the crypto library in the KDC server.
- Multiple integer overflows in the handling of TIFF files.
- A directory traversal issue exists in iChat's handling of inline image transfers.
- A symlink following issue exists in Folder Manager.
- Multiple errors in Adobe Flash Player plug-in.
- An uninitialized memory read issue exists in the CUPS web interface's handling of form variables.
- An use after free error exists in cupsd.
- A cross-site request forgery issue exists in the CUPS web interface.
Vulnerability Impact: Successful exploitation will allow attacker to conduct cross-site scripting attack, access sensitive information, cause an unexpected application termination or arbitrary code execution, upload files to arbitrary locations on the filesystem of a user and cause privilege escalation.
Affected Software/OS: Apple Mac OS X and Mac OS X Server version 10.5.8, 10.6 through 10.6.3
Solution: The vendor has released updates. Please see the references for more information.
CVSS Score: 10.0
CVSS Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C
|