Mac OS X Multiple Vulnerabilities (Security Update 2006-006)

critical Nessus Plugin ID 22479

Synopsis

The remote host is missing a Mac OS X update which fixes a security issue.

Description

The remote host is running a version of Mac OS X 10.3 which does not have the security update 2006-006 applied.

Security Update 2006-006 contains several security fixes for the following programs :

- CFNetwork
- Flash Player
- QuickDraw Manager
- SASL
- WebCore

Solution

Upgrade to Mac OS X 10.4.8 :
http://www.apple.com/support/downloads/macosx1048updateintel.html http://www.apple.com/support/downloads/macosx1048updateppc.html

See Also

http://docs.info.apple.com/article.html?artnum=304460

Plugin Details

Severity: Critical

ID: 22479

File Name: macosx_SecUpd2006-006.nasl

Version: 1.19

Type: local

Agent: macosx

Published: 9/29/2006

Updated: 5/28/2024

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: High

Score: 8.9

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 8.3

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: cpe:/o:apple:mac_os_x:10.4

Required KB Items: Host/MacOSX/packages

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 9/29/2006

Vulnerability Publication Date: 7/31/2006

Exploitable With

Core Impact

Reference Information

CVE: CVE-2006-1721, CVE-2006-3311, CVE-2006-3587, CVE-2006-3588, CVE-2006-3946, CVE-2006-4387, CVE-2006-4390, CVE-2006-4391, CVE-2006-4392, CVE-2006-4393, CVE-2006-4394, CVE-2006-4395, CVE-2006-4397, CVE-2006-4399, CVE-2006-4640

BID: 20271

CWE: 264