Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.804062
Categoría:Mac OS X Local Security Checks
Título:Apple Mac OS X Directory Service Remote Buffer Overflow Vulnerability
Resumen:Apple Mac OS X is prone to a buffer overflow vulnerability.
Descripción:Summary:
Apple Mac OS X is prone to a buffer overflow vulnerability.

Vulnerability Insight:
Multiple flaws are due to improper
handling of network messages and multiple errors in ruby on rails.

Vulnerability Impact:
Successful exploitation will allow
attackers to, execute arbitrary code or cause a denial of service.

Affected Software/OS:
Apple Mac OS X version 10.6.8

Solution:
Apply the Mac Security Update 2013-002. Please see the references for more information.

CVSS Score:
10.0

CVSS Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2013-0984
http://lists.apple.com/archives/security-announce/2013/Jun/msg00000.html
Common Vulnerability Exposure (CVE) ID: CVE-2013-0155
Debian Security Information: DSA-2609 (Google Search)
http://www.debian.org/security/2013/dsa-2609
http://ics-cert.us-cert.gov/advisories/ICSA-13-036-01A
https://groups.google.com/group/rubyonrails-security/msg/bc6f13dafe130ee9?dmode=source&output=gplain
RedHat Security Advisories: RHSA-2013:0154
http://rhn.redhat.com/errata/RHSA-2013-0154.html
RedHat Security Advisories: RHSA-2013:0155
http://rhn.redhat.com/errata/RHSA-2013-0155.html
SuSE Security Announcement: openSUSE-SU-2013:1904 (Google Search)
http://lists.opensuse.org/opensuse-updates/2013-12/msg00079.html
SuSE Security Announcement: openSUSE-SU-2013:1906 (Google Search)
http://lists.opensuse.org/opensuse-updates/2013-12/msg00081.html
SuSE Security Announcement: openSUSE-SU-2013:1907 (Google Search)
http://lists.opensuse.org/opensuse-updates/2013-12/msg00082.html
SuSE Security Announcement: openSUSE-SU-2014:0009 (Google Search)
http://lists.opensuse.org/opensuse-updates/2014-01/msg00003.html
Common Vulnerability Exposure (CVE) ID: CVE-2013-0276
52112
http://secunia.com/advisories/52112
52774
http://secunia.com/advisories/52774
57896
http://www.securityfocus.com/bid/57896
90072
http://www.osvdb.org/90072
APPLE-SA-2013-06-04-1
DSA-2620
http://www.debian.org/security/2013/dsa-2620
RHSA-2013:0686
http://rhn.redhat.com/errata/RHSA-2013-0686.html
[oss-security] 20130211 Circumvention of attr_protected [CVE-2013-0276]
http://www.openwall.com/lists/oss-security/2013/02/11/5
[rubyonrails-security] 20130211 Circumvention of attr_protected [CVE-2013-0276]
https://groups.google.com/group/rubyonrails-security/msg/bb44b98a73ef1a06?dmode=source&output=gplain
http://support.apple.com/kb/HT5784
http://weblog.rubyonrails.org/2013/2/11/SEC-ANN-Rails-3-2-12-3-1-11-and-2-3-17-have-been-released/
openSUSE-SU-2013:0462
http://lists.opensuse.org/opensuse-updates/2013-03/msg00048.html
Common Vulnerability Exposure (CVE) ID: CVE-2013-0277
1028109
http://securitytracker.com/id?1028109
90073
http://www.osvdb.org/90073
[oss-security] 20130211 Serialized Attributes YAML Vulnerability with Rails 2.3 and 3.0 [CVE-2013-0277]
http://www.openwall.com/lists/oss-security/2013/02/11/6
[rubyonrails-security] 20130211 Serialized Attributes YAML Vulnerability with Rails 2.3 and 3.0 [CVE-2013-0277]
https://groups.google.com/group/rubyonrails-security/msg/302ec7ce90f13837?dmode=source&output=gplain
https://puppet.com/security/cve/cve-2013-0277
Common Vulnerability Exposure (CVE) ID: CVE-2013-0333
APPLE-SA-2013-03-14-1
http://lists.apple.com/archives/security-announce/2013/Mar/msg00002.html
DSA-2613
http://www.debian.org/security/2013/dsa-2613
RHSA-2013:0201
http://rhn.redhat.com/errata/RHSA-2013-0201.html
RHSA-2013:0202
http://rhn.redhat.com/errata/RHSA-2013-0202.html
RHSA-2013:0203
http://rhn.redhat.com/errata/RHSA-2013-0203.html
VU#628463
http://www.kb.cert.org/vuls/id/628463
[rubyonrails-security] 20130129 Vulnerability in JSON Parser in Ruby on Rails 3.0 and 2.3
https://groups.google.com/group/rubyonrails-security/msg/52179af76915e518?dmode=source&output=gplain
http://weblog.rubyonrails.org/2013/1/28/Rails-3-0-20-and-2-3-16-have-been-released/
https://puppet.com/security/cve/cve-2013-0333
Common Vulnerability Exposure (CVE) ID: CVE-2013-1854
APPLE-SA-2013-10-22-5
http://lists.apple.com/archives/security-announce/2013/Oct/msg00006.html
RHSA-2013:0699
http://rhn.redhat.com/errata/RHSA-2013-0699.html
RHSA-2014:1863
http://rhn.redhat.com/errata/RHSA-2014-1863.html
[ruby-security-ann] 20130318 [CVE-2013-1854] Symbol DoS vulnerability in Active Record
https://groups.google.com/group/ruby-security-ann/msg/34e0d780b04308de?dmode=source&output=gplain
http://weblog.rubyonrails.org/2013/3/18/SEC-ANN-Rails-3-2-13-3-1-12-and-2-3-18-have-been-released/
openSUSE-SU-2013:0659
http://lists.opensuse.org/opensuse-updates/2013-04/msg00070.html
openSUSE-SU-2013:0660
http://lists.opensuse.org/opensuse-updates/2013-04/msg00071.html
openSUSE-SU-2013:0664
http://lists.opensuse.org/opensuse-updates/2013-04/msg00075.html
openSUSE-SU-2013:0667
http://lists.opensuse.org/opensuse-updates/2013-04/msg00078.html
openSUSE-SU-2013:0668
http://lists.opensuse.org/opensuse-updates/2013-04/msg00079.html
Common Vulnerability Exposure (CVE) ID: CVE-2013-1855
RHSA-2013:0698
http://rhn.redhat.com/errata/RHSA-2013-0698.html
[rubyonrails-security] 20130318 [CVE-2013-1855] XSS vulnerability in sanitize_css in Action Pack
https://groups.google.com/group/rubyonrails-security/msg/8ed835a97cdd1afd?dmode=source&output=gplain
openSUSE-SU-2013:0661
http://lists.opensuse.org/opensuse-updates/2013-04/msg00072.html
openSUSE-SU-2013:0662
http://lists.opensuse.org/opensuse-updates/2013-04/msg00073.html
openSUSE-SU-2014:0019
http://lists.opensuse.org/opensuse-updates/2014-01/msg00013.html
Common Vulnerability Exposure (CVE) ID: CVE-2013-1856
[rubyonrails-security] 20130318 [CVE-2013-1856] XML Parsing Vulnerability affecting JRuby users
https://groups.google.com/group/rubyonrails-security/msg/6c2482d4ed1545e6?dmode=source&output=gplain
Common Vulnerability Exposure (CVE) ID: CVE-2013-1857
https://groups.google.com/group/rubyonrails-security/msg/78b9817a5943f6d6?dmode=source&output=gplain
RedHat Security Advisories: RHSA-2013:0698
RedHat Security Advisories: RHSA-2014:1863
SuSE Security Announcement: openSUSE-SU-2013:0661 (Google Search)
SuSE Security Announcement: openSUSE-SU-2013:0662 (Google Search)
SuSE Security Announcement: openSUSE-SU-2014:0019 (Google Search)
CopyrightCopyright (C) 2014 Greenbone AG

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.