Mac OS X 10.10.x < 10.10.5 多种漏洞

high Nessus 插件 ID 85408
全新!插件严重性现在使用 CVSS v3

计算的插件严重性默认已更新为使用 CVSS v3。没有 CVSS v3 分数的插件将回退到 CVSS v2 来计算严重性。可以在设置下拉列表中切换严重性显示首选项。

简介

远程主机缺少一个用于修复多种安全漏洞的 Mac OS X 更新。

描述

远程主机运行的 Mac OS X 10.10.x 版低于 10.10.5。因此,它受到以下组件中的多种漏洞影响:

- apache
- apache_mod_php
- Apple ID OD Plug-in
- AppleGraphicsControl
- Bluetooth
- bootp
- CloudKit
- CoreMedia Playback
- CoreText
- curl
- Data Detectors Engine
- Date & Time pref pane
- Dictionary Application
- DiskImages
- dyld
- FontParser
- groff
- ImageIO
- Install Framework Legacy
- IOFireWireFamily
- IOGraphics
- IOHIDFamily
- Kernel
- Libc
- Libinfo
- libpthread
- libxml2
- libxpc
- mail_cmds
- Notification Center OSX
- ntfs
- OpenSSH
- OpenSSL
- perl
- PostgreSQL
- python
- QL Office
- Quartz Composer Framework
- Quick Look
- QuickTime 7
- SceneKit
- Security
- SMBClient
- Speech UI
- sudo
- tcpdump
- Text Formats
- udf

请注意,如果成功利用最严重的问题则可能导致执行任意代码。

解决方案

升级到 Mac OS X 10.10.5 或更高版本。

另见

https://support.apple.com/en-us/HT205031

插件详情

严重性: High

ID: 85408

文件名: macosx_10_10_5.nasl

版本: 1.15

类型: combined

代理: macosx

发布时间: 2015/8/17

最近更新时间: 2018/7/16

依存关系: ssh_get_info.nasl, os_fingerprint.nasl

风险信息

VPR

风险因素: High

分数: 8.9

CVSS v2

风险因素: High

基本分数: 9.3

时间分数: 8.1

矢量: AV:N/AC:M/Au:N/C:C/I:C/A:C

时间矢量: E:H/RL:OF/RC:C

漏洞信息

CPE: cpe:/o:apple:mac_os_x

可利用: true

易利用性: Exploits are available

补丁发布日期: 2015/8/11

漏洞发布日期: 2009/7/24

可利用的方式

CANVAS (CANVAS)

Core Impact

Metasploit (Apple OS X DYLD_PRINT_TO_FILE Privilege Escalation)

参考资料信息

CVE: CVE-2009-5044, CVE-2009-5078, CVE-2012-6685, CVE-2013-1775, CVE-2013-1776, CVE-2013-2776, CVE-2013-2777, CVE-2013-7040, CVE-2013-7338, CVE-2013-7422, CVE-2014-0067, CVE-2014-0106, CVE-2014-0191, CVE-2014-1912, CVE-2014-3581, CVE-2014-3583, CVE-2014-3613, CVE-2014-3620, CVE-2014-3660, CVE-2014-3707, CVE-2014-7185, CVE-2014-7844, CVE-2014-8109, CVE-2014-8150, CVE-2014-8151, CVE-2014-8161, CVE-2014-8767, CVE-2014-8769, CVE-2014-9140, CVE-2014-9365, CVE-2014-9680, CVE-2015-0228, CVE-2015-0241, CVE-2015-0242, CVE-2015-0243, CVE-2015-0244, CVE-2015-0253, CVE-2015-1788, CVE-2015-1789, CVE-2015-1790, CVE-2015-1791, CVE-2015-1792, CVE-2015-2783, CVE-2015-2787, CVE-2015-3143, CVE-2015-3144, CVE-2015-3145, CVE-2015-3148, CVE-2015-3153, CVE-2015-3183, CVE-2015-3185, CVE-2015-3307, CVE-2015-3329, CVE-2015-3330, CVE-2015-3729, CVE-2015-3730, CVE-2015-3731, CVE-2015-3732, CVE-2015-3733, CVE-2015-3734, CVE-2015-3735, CVE-2015-3736, CVE-2015-3737, CVE-2015-3738, CVE-2015-3739, CVE-2015-3740, CVE-2015-3741, CVE-2015-3742, CVE-2015-3743, CVE-2015-3744, CVE-2015-3745, CVE-2015-3746, CVE-2015-3747, CVE-2015-3748, CVE-2015-3749, CVE-2015-3750, CVE-2015-3751, CVE-2015-3752, CVE-2015-3753, CVE-2015-3754, CVE-2015-3755, CVE-2015-3757, CVE-2015-3760, CVE-2015-3761, CVE-2015-3762, CVE-2015-3764, CVE-2015-3765, CVE-2015-3766, CVE-2015-3767, CVE-2015-3768, CVE-2015-3769, CVE-2015-3770, CVE-2015-3771, CVE-2015-3772, CVE-2015-3773, CVE-2015-3774, CVE-2015-3775, CVE-2015-3776, CVE-2015-3777, CVE-2015-3778, CVE-2015-3779, CVE-2015-3780, CVE-2015-3781, CVE-2015-3782, CVE-2015-3783, CVE-2015-3784, CVE-2015-3786, CVE-2015-3787, CVE-2015-3788, CVE-2015-3789, CVE-2015-3790, CVE-2015-3791, CVE-2015-3792, CVE-2015-3794, CVE-2015-3795, CVE-2015-3796, CVE-2015-3797, CVE-2015-3798, CVE-2015-3799, CVE-2015-3800, CVE-2015-3802, CVE-2015-3803, CVE-2015-3804, CVE-2015-3805, CVE-2015-3806, CVE-2015-3807, CVE-2015-4021, CVE-2015-4022, CVE-2015-4024, CVE-2015-4025, CVE-2015-4026, CVE-2015-4147, CVE-2015-4148, CVE-2015-5600, CVE-2015-5747, CVE-2015-5748, CVE-2015-5750, CVE-2015-5751, CVE-2015-5753, CVE-2015-5754, CVE-2015-5755, CVE-2015-5756, CVE-2015-5757, CVE-2015-5758, CVE-2015-5761, CVE-2015-5763, CVE-2015-5768, CVE-2015-5771, CVE-2015-5772, CVE-2015-5773, CVE-2015-5774, CVE-2015-5775, CVE-2015-5776, CVE-2015-5777, CVE-2015-5778, CVE-2015-5779, CVE-2015-5781, CVE-2015-5782, CVE-2015-5783, CVE-2015-5784

BID: 36381, 58203, 58207, 62741, 64194, 65179, 65379, 65721, 65997, 67233, 69742, 69748, 70089, 70644, 70988, 71150, 71153, 71468, 71639, 71656, 71657, 71701, 71964, 72538, 72540, 72542, 72543, 72649, 72981, 73040, 73041, 73357, 73431, 74174, 74204, 74239, 74240, 74299, 74300, 74301, 74303, 74408, 74700, 74703, 74902, 74903, 74904, 75056, 75103, 75154, 75156, 75157, 75158, 75161, 75704, 75963, 75964, 75965, 75990, 76337, 76338, 76339, 76340, 76341, 76342, 76343, 76344

APPLE-SA: APPLE-SA-2015-08-13-2