Description: | Summary: Apple Mac OS X is prone to multiple vulnerabilities.
Vulnerability Insight: Multiple flaws exist due to:
- Multiple issues in zlib, SQLite, ntp, expat and files.
- Multiple memory corruption issues.
- A certificate validation issue existed in the handling of revocation data.
- Window management, memory consumption and validation issues.
- An encryption issue existed in the handling of mail drafts.
- Turning off 'Load remote content in messages' did not apply to all mailboxes.
- A resource exhaustion issue in 'glob' function.
- A permissions issue existed in the handling of the Apple ID.
- An out-of-bounds read error.
- The security state of the captive portal browser was not obvious.
- An upgrade issue existed in the handling of firewall settings.
- Some unspecified errors.
For more information about the vulnerabilities refer to Reference links.
Vulnerability Impact: Successful exploitation of these vulnerabilities allow remote attackers to execute arbitrary code, bypass security restrictions, disclose sensitive information and cause a denial of service on affected system.
Affected Software/OS: Apple Mac OS X version 10.8 through 10.12.x prior to 10.13
Solution: Upgrade to Apple Mac OS X version 10.13 or later.
Note: According to the vendor an upgrade to version 10.13 is required to mitigate these vulnerabilities. Please see the advisory (HT208144) for more info.
CVSS Score: 10.0
CVSS Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C
|