Mac OS X 10.4.x < 10.4.8 Multiple Vulnerabilities

critical Nessus Plugin ID 22476

Synopsis

The remote host is missing a Mac OS X update which fixes a security issue.

Description

The remote host is running a version of Mac OS X 10.4.x that is prior to 10.4.8.

Mac OS X 10.4.8 contains several security fixes for the following programs :

- CFNetwork
- Flash Player
- ImageIO
- Kernel
- LoginWindow
- Preferences
- QuickDraw Manager
- SASL
- WebCore
- Workgroup Manager

Solution

Upgrade to Mac OS X 10.4.8 :
http://www.apple.com/support/downloads/macosx1048updateintel.html http://www.apple.com/support/downloads/macosx1048updateppc.html http://www.apple.com/support/downloads/macosxserver1048update.html

See Also

http://docs.info.apple.com/article.html?artnum=304460

Plugin Details

Severity: Critical

ID: 22476

File Name: macosx_10_4_8.nasl

Version: 1.19

Type: local

Agent: macosx

Published: 9/29/2006

Updated: 5/28/2024

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: High

Score: 8.9

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 8.3

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: cpe:/o:apple:mac_os_x:10.4

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 11/14/2006

Vulnerability Publication Date: 4/7/2006

Exploitable With

Core Impact

Reference Information

CVE: CVE-2006-1721, CVE-2006-3311, CVE-2006-3587, CVE-2006-3588, CVE-2006-3946, CVE-2006-4387, CVE-2006-4390, CVE-2006-4391, CVE-2006-4392, CVE-2006-4393, CVE-2006-4394, CVE-2006-4395, CVE-2006-4397, CVE-2006-4399, CVE-2006-4640

BID: 20271

CWE: 264