ID

VAR-200909-0752


CVE

CVE-2009-2814


TITLE

Apple Mac OS of Wiki Server Vulnerable to cross-site scripting

Trust: 0.8

sources: JVNDB: JVNDB-2009-002139

DESCRIPTION

Cross-site scripting (XSS) vulnerability in the Wiki Server in Apple Mac OS X 10.5.8 allows remote attackers to inject arbitrary web script or HTML via a search request containing data that does not use UTF-8 encoding. An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks. This issue affects Mac OS X Server 10.5.8 and prior. NOTE: This issue was previously covered in BID 36349 (Apple Mac OS X 2009-005 Multiple Security Vulnerabilities), but has been assigned its own record to better document it. ---------------------------------------------------------------------- Do you have VARM strategy implemented? (Vulnerability Assessment Remediation Management) If not, then implement it through the most reliable vulnerability intelligence source on the market. Implement it through Secunia. 1) An error in Alias Manager when processing alias files can be exploited to cause a buffer overflow and potentially execute arbitrary code. 2) An error in Resource Manager when processing resource forks can be exploited to corrupt memory and potentially execute arbitrary code. 3) Multiple vulnerabilities in ClamAV can be exploited to bypass certain security restrictions, cause a DoS, and potentially compromise a vulnerable system. For more information: SA34566 SA34612 4) An integer overflow error exists when processing ColorSync profiles embedded in images. This can be exploited to cause a heap-based buffer overflow and potentially execute arbitrary code via a specially crafted image. 5) An integer overflow error exists in CoreGraphics when processing JBIG2 streams embedded in PDF files. This can be exploited to cause a heap-based buffer overflow and potentially execute arbitrary code via a specially crafted PDF file. 6) An error in CoreGraphics can be exploited to cause a heap-based buffer overflow potentially execute arbitrary code when drawing long text strings. This is related to vulnerability #1 in: SA36269 7) A NULL-pointer dereference error in CUPS can be exploited to cause a crash. For more information see vulnerability #4 in: SA34481 8) An error in the CUPS USB backend can be exploited to cause a heap-based buffer overflow and execute arbitrary code with escalated privileges. 9) Multiple vulnerabilities in Adobe Flash Player can be exploited by malicious people to bypass security features, gain knowledge of sensitive information, or compromise a user's system. For more information: SA35948 10) Multiple errors exist in ImageIO when processing PixarFilm encoded TIFF images. These can be exploited to trigger memory corruptions and potentially execute arbitrary code via specially crafted TIFF files. 11) An error exists in Launch Services when handling files having a ".fileloc" extension. 12) An error exists in Launch Services when handling exported document types presented when an application is downloaded. This can be exploited to associate a safe file extension with an unsafe Uniform Type Identifier (UTI) and execute arbitrary code. 13) An error in MySQL can be exploited by malicious, local users to bypass certain security restrictions. For more information: SA30134 14) Multiple vulnerabilities in PHP have an unknown impact or can potentially be exploited by malicious people to disclose sensitive information or cause a DoS (Denial of Service). For more information: SA34081 15) An error exists in Samba when handling error conditions. This can be exploited by a user without a configured home directory to access the contents of the file system by connecting to the Windows File Sharing service. 16) Input passed in search requests containing non UTF-8 encoded data to Wiki Server is not properly sanitised before being returned to the user. Security Update 2009-005 (Tiger PPC): http://support.apple.com/downloads/DL931/en_US/SecUpd2009-005PPC.dmg Security Update 2009-005 (Tiger Intel): http://support.apple.com/downloads/DL932/en_US/SecUpd2009-005Intel.dmg Security Update 2009-005 Server (Tiger Univ): http://support.apple.com/downloads/DL933/en_US/SecUpdSrvr2009-005Univ.dmg Security Update 2009-005 Server (Tiger PPC): http://support.apple.com/downloads/DL934/en_US/SecUpdSrvr2009-005PPC.dmg Mac OS X Server v10.6.1 Update: http://support.apple.com/downloads/DL929/en_US/MacOSXServerUpd10.6.1.dmg Security Update 2009-005 Server (Leopard): http://support.apple.com/downloads/DL936/en_US/SecUpdSrvr2009-005.dmg Security Update 2009-005 (Leopard): http://support.apple.com/downloads/DL935/en_US/SecUpd2009-005.dmg Mac OS X v10.6.1 Update: http://support.apple.com/downloads/DL930/en_US/MacOSXUpd10.6.1.dmg PROVIDED AND/OR DISCOVERED BY: 1, 2, 4, 8, 10-12, 16) Reported by the vendor. 5) The vendor credits Will Dormann of CERT/CC. 6) The vendor credits Will Drewry of Google. 15) The vendor credits J. David Hester of LCG Systems National Institutes of Health. ORIGINAL ADVISORY: http://support.apple.com/kb/HT3864 http://support.apple.com/kb/HT3865 OTHER REFERENCES: SA30134: http://secunia.com/advisories/30134/ SA34081: http://secunia.com/advisories/34081/ SA34481: http://secunia.com/advisories/34481/ SA34566: http://secunia.com/advisories/34566/ SA34612: http://secunia.com/advisories/34612/ SA35948: http://secunia.com/advisories/35948/ SA36269: http://secunia.com/advisories/36269/ ---------------------------------------------------------------------- About: This Advisory was delivered by Secunia as a free service to help everybody keeping their systems up to date against the latest vulnerabilities. Subscribe: http://secunia.com/advisories/secunia_security_advisories/ Definitions: (Criticality, Where etc.) http://secunia.com/advisories/about_secunia_advisories/ Please Note: Secunia recommends that you verify all advisories you receive by clicking the link. Secunia NEVER sends attached files with advisories. Secunia does not advise people to install third party patches, only use those supplied by the vendor. ---------------------------------------------------------------------- Unsubscribe: Secunia Security Advisories http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org ----------------------------------------------------------------------

Trust: 2.07

sources: NVD: CVE-2009-2814 // JVNDB: JVNDB-2009-002139 // BID: 36364 // VULHUB: VHN-40260 // PACKETSTORM: 81208

AFFECTED PRODUCTS

vendor:applemodel:mac os x serverscope:eqversion:10.5.8

Trust: 1.6

vendor:applemodel:mac os x serverscope:eqversion:v10.5.8

Trust: 0.8

vendor:applemodel:mac os serverscope:eqversion:x10.5.8

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x10.5.7

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x10.5.6

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x10.5.5

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x10.5.4

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x10.5.3

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x10.5.2

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x10.5.1

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x10.5

Trust: 0.3

sources: BID: 36364 // JVNDB: JVNDB-2009-002139 // CNNVD: CNNVD-200909-282 // NVD: CVE-2009-2814

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2009-2814
value: MEDIUM

Trust: 1.0

NVD: CVE-2009-2814
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-200909-282
value: MEDIUM

Trust: 0.6

VULHUB: VHN-40260
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2009-2814
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-40260
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-40260 // JVNDB: JVNDB-2009-002139 // CNNVD: CNNVD-200909-282 // NVD: CVE-2009-2814

PROBLEMTYPE DATA

problemtype:CWE-79

Trust: 1.9

sources: VULHUB: VHN-40260 // JVNDB: JVNDB-2009-002139 // NVD: CVE-2009-2814

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200909-282

TYPE

XSS

Trust: 0.6

sources: CNNVD: CNNVD-200909-282

CONFIGURATIONS

sources: JVNDB: JVNDB-2009-002139

PATCH

title:HT3865url:http://support.apple.com/kb/HT3865

Trust: 0.8

title:HT3865url:http://support.apple.com/kb/HT3865?viewlocale=ja_JP

Trust: 0.8

sources: JVNDB: JVNDB-2009-002139

EXTERNAL IDS

db:NVDid:CVE-2009-2814

Trust: 2.8

db:SECUNIAid:36701

Trust: 2.6

db:BIDid:36364

Trust: 1.4

db:OSVDBid:57956

Trust: 1.1

db:JVNDBid:JVNDB-2009-002139

Trust: 0.8

db:CNNVDid:CNNVD-200909-282

Trust: 0.7

db:APPLEid:APPLE-SA-2009-09-10-2

Trust: 0.6

db:VULHUBid:VHN-40260

Trust: 0.1

db:PACKETSTORMid:81208

Trust: 0.1

sources: VULHUB: VHN-40260 // BID: 36364 // JVNDB: JVNDB-2009-002139 // PACKETSTORM: 81208 // CNNVD: CNNVD-200909-282 // NVD: CVE-2009-2814

REFERENCES

url:http://secunia.com/advisories/36701

Trust: 2.5

url:http://support.apple.com/kb/ht3865

Trust: 1.8

url:http://lists.apple.com/archives/security-announce/2009/sep/msg00004.html

Trust: 1.7

url:http://www.securityfocus.com/bid/36364

Trust: 1.1

url:http://osvdb.org/57956

Trust: 1.1

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/53175

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2009-2814

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2009-2814

Trust: 0.8

url:http://www.apple.com/macosx/

Trust: 0.3

url:http://secunia.com/advisories/35948/

Trust: 0.1

url:http://support.apple.com/downloads/dl936/en_us/secupdsrvr2009-005.dmg

Trust: 0.1

url:http://support.apple.com/downloads/dl933/en_us/secupdsrvr2009-005univ.dmg

Trust: 0.1

url:http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org

Trust: 0.1

url:http://secunia.com/advisories/34481/

Trust: 0.1

url:http://secunia.com/advisories/about_secunia_advisories/

Trust: 0.1

url:http://support.apple.com/downloads/dl932/en_us/secupd2009-005intel.dmg

Trust: 0.1

url:http://secunia.com/advisories/36269/

Trust: 0.1

url:http://secunia.com/advisories/secunia_security_advisories/

Trust: 0.1

url:http://secunia.com/advisories/business_solutions/

Trust: 0.1

url:http://support.apple.com/kb/ht3864

Trust: 0.1

url:http://support.apple.com/downloads/dl930/en_us/macosxupd10.6.1.dmg

Trust: 0.1

url:http://secunia.com/advisories/34566/

Trust: 0.1

url:http://support.apple.com/downloads/dl935/en_us/secupd2009-005.dmg

Trust: 0.1

url:http://secunia.com/advisories/36701/

Trust: 0.1

url:http://support.apple.com/downloads/dl934/en_us/secupdsrvr2009-005ppc.dmg

Trust: 0.1

url:http://support.apple.com/downloads/dl931/en_us/secupd2009-005ppc.dmg

Trust: 0.1

url:http://secunia.com/advisories/34081/

Trust: 0.1

url:http://secunia.com/advisories/34612/

Trust: 0.1

url:http://secunia.com/advisories/30134/

Trust: 0.1

url:http://support.apple.com/downloads/dl929/en_us/macosxserverupd10.6.1.dmg

Trust: 0.1

sources: VULHUB: VHN-40260 // BID: 36364 // JVNDB: JVNDB-2009-002139 // PACKETSTORM: 81208 // CNNVD: CNNVD-200909-282 // NVD: CVE-2009-2814

CREDITS

J. David Hester

Trust: 0.6

sources: CNNVD: CNNVD-200909-282

SOURCES

db:VULHUBid:VHN-40260
db:BIDid:36364
db:JVNDBid:JVNDB-2009-002139
db:PACKETSTORMid:81208
db:CNNVDid:CNNVD-200909-282
db:NVDid:CVE-2009-2814

LAST UPDATE DATE

2025-04-10T22:35:01.799000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-40260date:2017-08-17T00:00:00
db:BIDid:36364date:2009-09-11T15:31:00
db:JVNDBid:JVNDB-2009-002139date:2009-10-23T00:00:00
db:CNNVDid:CNNVD-200909-282date:2009-09-16T00:00:00
db:NVDid:CVE-2009-2814date:2025-04-09T00:30:58.490

SOURCES RELEASE DATE

db:VULHUBid:VHN-40260date:2009-09-14T00:00:00
db:BIDid:36364date:2009-09-10T00:00:00
db:JVNDBid:JVNDB-2009-002139date:2009-10-23T00:00:00
db:PACKETSTORMid:81208date:2009-09-11T14:30:33
db:CNNVDid:CNNVD-200909-282date:2009-09-14T00:00:00
db:NVDid:CVE-2009-2814date:2009-09-14T16:30:00.467