OS X 10.4 - Remote hacker automatic control
Version: | 10.4.10 and prior. |
Technical Details: | OS X 10.4.11 and Security Update 2007-008 have been released, addressing numerous serious vulnerabilities, including:
|
Description: |
Apple Inc have released a cumulative update for OS X 10.4, bringing it to 10.4.11, and have released a separate Security Update 2007-008, for OS X 10.3.x systems (included in the 10.4.11 update). The update provides fixes for multiple serious vulnerabilities, including for AppleRAID, BIND, bzip2, CoreFoundation, and other system components. Vulnerabilities range from denial of service and local privilege escalation, through to automatic remote code execution. |
Mitigation: |
Apply the update to OS X 10.4.11 or Security Update 2007-008 (OS X 10.3.x systems) at the earliest opportunity, either from the Software Update option in the Apple Menu, or from Apple's download link, below. If the Software Update application is used, only the applicable update will be selected and installed on a vulnerable system. |
Updates: |
http://www.apple.com/support/downloads/ |
Source: |
http://docs.info.apple.com/article.html?artnum=61798 |
Exploits: |
|
External Tracking Data: | CVE-ID: CVE-2007-4678 (AppleRAID) CVE-ID: CVE-2007-2926 (BIND) CVE-ID: CVE-2005-0953 (bzip2) CVE-ID: CVE-2005-1260 (bzip2) CVE-ID: CVE-2007-4679 (CFFTP) CVE-ID: CVE-2007-4680 (CFNetwork) CVE-ID: CVE-2007-0464 (CFNetwork) CVE-ID: CVE-2007-4681 (CoreFoundation) CVE-ID: CVE-2007-4682 (CoreText) CVE-ID: CVE-2007-3456 (Flash Player) CVE-ID: CVE-2007-3999 (Kerberos) CVE-ID: CVE-2007-4743 (Kerberos) CVE-ID: CVE-2007-3749 (Kernel) CVE-ID: CVE-2007-4683 (Kernel) CVE-ID: CVE-2007-4684 (Kernel) CVE-ID: CVE-2007-4685 (Kernel) CVE-ID: CVE-2006-6127 (Kernel) CVE-ID: CVE-2007-4686 (Kernel) CVE-ID: CVE-2007-4688 (Networking) CVE-ID: CVE-2007-4269 (Networking) CVE-ID: CVE-2007-4689 (Networking) CVE-ID: CVE-2007-4267 (Networking) CVE-ID: CVE-2007-4268 (Networking) CVE-ID: CVE-2007-4690 (NFS) CVE-ID: CVE-2007-4691 (NSURL) CVE-ID: CVE-2007-4687 (remote_cmds) CVE-ID: CVE-2007-0646 (Safari) CVE-ID: CVE-2007-4692 (Safari) CVE-ID: CVE-2007-4693 (SecurityAgent) CVE-ID: CVE-2007-4694 (WebCore) CVE-ID: CVE-2007-4695 (WebCore) CVE-ID: CVE-2007-4696 (WebCore) CVE-ID: CVE-2007-4697 (WebCore) CVE-ID: CVE-2007-4698 (WebCore) CVE-ID: CVE-2007-3758 (WebCore) CVE-ID: CVE-2007-3760 (WebCore) CVE-ID: CVE-2007-4671 (WebCore) CVE-ID: CVE-2007-3756 (WebCore) CVE-ID: CVE-2007-4699 (WebKit) CVE-ID: CVE-2007-4700 (WebKit) CVE-ID: CVE-2007-4701 (WebKit) |
Social bookmark this page