Mac OS X Multiple Vulnerabilities (Security Update 2007-005)

critical Nessus Plugin ID 25297

Synopsis

The remote host is missing a Mac OS X update that fixes several security issues.

Description

The remote host is running a version of Mac OS X 10.4 or 10.3 that does not have Security Update 2007-005 applied.

This update fixes security flaws in the following applications :

Alias Manager BIND CoreGraphics crontabs fetchmail file iChat mDNSResponder PPP ruby screen texinfo VPN

Solution

Install Security Update 2007-005 :

http://www.apple.com/support/downloads/securityupdate2007005universal.html

See Also

http://docs.info.apple.com/article.html?artnum=305530

Plugin Details

Severity: Critical

ID: 25297

File Name: macosx_SecUpd2007-005.nasl

Version: 1.19

Type: local

Agent: macosx

Published: 5/25/2007

Updated: 5/28/2024

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: High

Score: 7.4

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 8.3

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: cpe:/o:apple:mac_os_x:10.3, cpe:/o:apple:mac_os_x:10.4

Required KB Items: Host/MacOSX/packages

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 5/29/2007

Vulnerability Publication Date: 9/14/2005

Exploitable With

Core Impact

Metasploit (Mac OS X mDNSResponder UPnP Location Overflow)

Reference Information

CVE: CVE-2005-3011, CVE-2006-4095, CVE-2006-4096, CVE-2006-4573, CVE-2006-5467, CVE-2006-6303, CVE-2007-0493, CVE-2007-0494, CVE-2007-0740, CVE-2007-0750, CVE-2007-0751, CVE-2007-0752, CVE-2007-0753, CVE-2007-1536, CVE-2007-1558, CVE-2007-2386, CVE-2007-2390

BID: 24144, 24159

CWE: 134, 399