Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.804062
Category:Mac OS X Local Security Checks
Title:Apple Mac OS X Directory Service Remote Buffer Overflow Vulnerability
Summary:Apple Mac OS X is prone to a buffer overflow vulnerability.
Description:Summary:
Apple Mac OS X is prone to a buffer overflow vulnerability.

Vulnerability Insight:
Multiple flaws are due to improper
handling of network messages and multiple errors in ruby on rails.

Vulnerability Impact:
Successful exploitation will allow
attackers to, execute arbitrary code or cause a denial of service.

Affected Software/OS:
Apple Mac OS X version 10.6.8

Solution:
Apply the Mac Security Update 2013-002. Please see the references for more information.

CVSS Score:
10.0

CVSS Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2013-0984
http://lists.apple.com/archives/security-announce/2013/Jun/msg00000.html
Common Vulnerability Exposure (CVE) ID: CVE-2013-0155
Debian Security Information: DSA-2609 (Google Search)
http://www.debian.org/security/2013/dsa-2609
http://ics-cert.us-cert.gov/advisories/ICSA-13-036-01A
https://groups.google.com/group/rubyonrails-security/msg/bc6f13dafe130ee9?dmode=source&output=gplain
RedHat Security Advisories: RHSA-2013:0154
http://rhn.redhat.com/errata/RHSA-2013-0154.html
RedHat Security Advisories: RHSA-2013:0155
http://rhn.redhat.com/errata/RHSA-2013-0155.html
SuSE Security Announcement: openSUSE-SU-2013:1904 (Google Search)
http://lists.opensuse.org/opensuse-updates/2013-12/msg00079.html
SuSE Security Announcement: openSUSE-SU-2013:1906 (Google Search)
http://lists.opensuse.org/opensuse-updates/2013-12/msg00081.html
SuSE Security Announcement: openSUSE-SU-2013:1907 (Google Search)
http://lists.opensuse.org/opensuse-updates/2013-12/msg00082.html
SuSE Security Announcement: openSUSE-SU-2014:0009 (Google Search)
http://lists.opensuse.org/opensuse-updates/2014-01/msg00003.html
Common Vulnerability Exposure (CVE) ID: CVE-2013-0276
52112
http://secunia.com/advisories/52112
52774
http://secunia.com/advisories/52774
57896
http://www.securityfocus.com/bid/57896
90072
http://www.osvdb.org/90072
APPLE-SA-2013-06-04-1
DSA-2620
http://www.debian.org/security/2013/dsa-2620
RHSA-2013:0686
http://rhn.redhat.com/errata/RHSA-2013-0686.html
[oss-security] 20130211 Circumvention of attr_protected [CVE-2013-0276]
http://www.openwall.com/lists/oss-security/2013/02/11/5
[rubyonrails-security] 20130211 Circumvention of attr_protected [CVE-2013-0276]
https://groups.google.com/group/rubyonrails-security/msg/bb44b98a73ef1a06?dmode=source&output=gplain
http://support.apple.com/kb/HT5784
http://weblog.rubyonrails.org/2013/2/11/SEC-ANN-Rails-3-2-12-3-1-11-and-2-3-17-have-been-released/
openSUSE-SU-2013:0462
http://lists.opensuse.org/opensuse-updates/2013-03/msg00048.html
Common Vulnerability Exposure (CVE) ID: CVE-2013-0277
1028109
http://securitytracker.com/id?1028109
90073
http://www.osvdb.org/90073
[oss-security] 20130211 Serialized Attributes YAML Vulnerability with Rails 2.3 and 3.0 [CVE-2013-0277]
http://www.openwall.com/lists/oss-security/2013/02/11/6
[rubyonrails-security] 20130211 Serialized Attributes YAML Vulnerability with Rails 2.3 and 3.0 [CVE-2013-0277]
https://groups.google.com/group/rubyonrails-security/msg/302ec7ce90f13837?dmode=source&output=gplain
https://puppet.com/security/cve/cve-2013-0277
Common Vulnerability Exposure (CVE) ID: CVE-2013-0333
APPLE-SA-2013-03-14-1
http://lists.apple.com/archives/security-announce/2013/Mar/msg00002.html
DSA-2613
http://www.debian.org/security/2013/dsa-2613
RHSA-2013:0201
http://rhn.redhat.com/errata/RHSA-2013-0201.html
RHSA-2013:0202
http://rhn.redhat.com/errata/RHSA-2013-0202.html
RHSA-2013:0203
http://rhn.redhat.com/errata/RHSA-2013-0203.html
VU#628463
http://www.kb.cert.org/vuls/id/628463
[rubyonrails-security] 20130129 Vulnerability in JSON Parser in Ruby on Rails 3.0 and 2.3
https://groups.google.com/group/rubyonrails-security/msg/52179af76915e518?dmode=source&output=gplain
http://weblog.rubyonrails.org/2013/1/28/Rails-3-0-20-and-2-3-16-have-been-released/
https://puppet.com/security/cve/cve-2013-0333
Common Vulnerability Exposure (CVE) ID: CVE-2013-1854
APPLE-SA-2013-10-22-5
http://lists.apple.com/archives/security-announce/2013/Oct/msg00006.html
RHSA-2013:0699
http://rhn.redhat.com/errata/RHSA-2013-0699.html
RHSA-2014:1863
http://rhn.redhat.com/errata/RHSA-2014-1863.html
[ruby-security-ann] 20130318 [CVE-2013-1854] Symbol DoS vulnerability in Active Record
https://groups.google.com/group/ruby-security-ann/msg/34e0d780b04308de?dmode=source&output=gplain
http://weblog.rubyonrails.org/2013/3/18/SEC-ANN-Rails-3-2-13-3-1-12-and-2-3-18-have-been-released/
openSUSE-SU-2013:0659
http://lists.opensuse.org/opensuse-updates/2013-04/msg00070.html
openSUSE-SU-2013:0660
http://lists.opensuse.org/opensuse-updates/2013-04/msg00071.html
openSUSE-SU-2013:0664
http://lists.opensuse.org/opensuse-updates/2013-04/msg00075.html
openSUSE-SU-2013:0667
http://lists.opensuse.org/opensuse-updates/2013-04/msg00078.html
openSUSE-SU-2013:0668
http://lists.opensuse.org/opensuse-updates/2013-04/msg00079.html
Common Vulnerability Exposure (CVE) ID: CVE-2013-1855
RHSA-2013:0698
http://rhn.redhat.com/errata/RHSA-2013-0698.html
[rubyonrails-security] 20130318 [CVE-2013-1855] XSS vulnerability in sanitize_css in Action Pack
https://groups.google.com/group/rubyonrails-security/msg/8ed835a97cdd1afd?dmode=source&output=gplain
openSUSE-SU-2013:0661
http://lists.opensuse.org/opensuse-updates/2013-04/msg00072.html
openSUSE-SU-2013:0662
http://lists.opensuse.org/opensuse-updates/2013-04/msg00073.html
openSUSE-SU-2014:0019
http://lists.opensuse.org/opensuse-updates/2014-01/msg00013.html
Common Vulnerability Exposure (CVE) ID: CVE-2013-1856
[rubyonrails-security] 20130318 [CVE-2013-1856] XML Parsing Vulnerability affecting JRuby users
https://groups.google.com/group/rubyonrails-security/msg/6c2482d4ed1545e6?dmode=source&output=gplain
Common Vulnerability Exposure (CVE) ID: CVE-2013-1857
https://groups.google.com/group/rubyonrails-security/msg/78b9817a5943f6d6?dmode=source&output=gplain
RedHat Security Advisories: RHSA-2013:0698
RedHat Security Advisories: RHSA-2014:1863
SuSE Security Announcement: openSUSE-SU-2013:0661 (Google Search)
SuSE Security Announcement: openSUSE-SU-2013:0662 (Google Search)
SuSE Security Announcement: openSUSE-SU-2014:0019 (Google Search)
CopyrightCopyright (C) 2014 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.