ID

VAR-200909-0763


CVE

CVE-2009-2811


TITLE

Apple Mac OS of Launch Services Vulnerable to arbitrary code execution

Trust: 0.8

sources: JVNDB: JVNDB-2009-002136

DESCRIPTION

Incomplete blacklist vulnerability in Launch Services in Apple Mac OS X 10.5.8 allows user-assisted remote attackers to execute arbitrary code via a .fileloc file, which does not trigger a "potentially unsafe" warning message in the Quarantine feature. Apple Mac OS X is prone to a vulnerability that may allow attackers to bypass certain security warnings. The issue affects the Launch Services component. Successfully exploiting this issue may allow attackers to bypass certain security warnings and trick a user into opening unsafe malicious files. The following versions are affected: Mac OS X 10.5.8 and prior Mac OS X Server 10.5.8 and prior NOTE: This issue was previously covered in BID 36349 (Apple Mac OS X 2009-005 Multiple Security Vulnerabilities), but has been assigned its own record to better document it. This update adds the .fileloc type to the category of content types that the system flags as unsafe in certain circumstances (such as when downloading from mail). Although this content type is not automatically opened, it may execute malicious payloads if opened manually. ---------------------------------------------------------------------- Do you have VARM strategy implemented? (Vulnerability Assessment Remediation Management) If not, then implement it through the most reliable vulnerability intelligence source on the market. Implement it through Secunia. 1) An error in Alias Manager when processing alias files can be exploited to cause a buffer overflow and potentially execute arbitrary code. 2) An error in Resource Manager when processing resource forks can be exploited to corrupt memory and potentially execute arbitrary code. 3) Multiple vulnerabilities in ClamAV can be exploited to bypass certain security restrictions, cause a DoS, and potentially compromise a vulnerable system. For more information: SA34566 SA34612 4) An integer overflow error exists when processing ColorSync profiles embedded in images. This can be exploited to cause a heap-based buffer overflow and potentially execute arbitrary code via a specially crafted image. 5) An integer overflow error exists in CoreGraphics when processing JBIG2 streams embedded in PDF files. This can be exploited to cause a heap-based buffer overflow and potentially execute arbitrary code via a specially crafted PDF file. 6) An error in CoreGraphics can be exploited to cause a heap-based buffer overflow potentially execute arbitrary code when drawing long text strings. This is related to vulnerability #1 in: SA36269 7) A NULL-pointer dereference error in CUPS can be exploited to cause a crash. For more information see vulnerability #4 in: SA34481 8) An error in the CUPS USB backend can be exploited to cause a heap-based buffer overflow and execute arbitrary code with escalated privileges. 9) Multiple vulnerabilities in Adobe Flash Player can be exploited by malicious people to bypass security features, gain knowledge of sensitive information, or compromise a user's system. For more information: SA35948 10) Multiple errors exist in ImageIO when processing PixarFilm encoded TIFF images. These can be exploited to trigger memory corruptions and potentially execute arbitrary code via specially crafted TIFF files. 11) An error exists in Launch Services when handling files having a ".fileloc" extension. 12) An error exists in Launch Services when handling exported document types presented when an application is downloaded. This can be exploited to associate a safe file extension with an unsafe Uniform Type Identifier (UTI) and execute arbitrary code. For more information: SA30134 14) Multiple vulnerabilities in PHP have an unknown impact or can potentially be exploited by malicious people to disclose sensitive information or cause a DoS (Denial of Service). For more information: SA34081 15) An error exists in Samba when handling error conditions. This can be exploited by a user without a configured home directory to access the contents of the file system by connecting to the Windows File Sharing service. 16) Input passed in search requests containing non UTF-8 encoded data to Wiki Server is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site. Security Update 2009-005 (Tiger PPC): http://support.apple.com/downloads/DL931/en_US/SecUpd2009-005PPC.dmg Security Update 2009-005 (Tiger Intel): http://support.apple.com/downloads/DL932/en_US/SecUpd2009-005Intel.dmg Security Update 2009-005 Server (Tiger Univ): http://support.apple.com/downloads/DL933/en_US/SecUpdSrvr2009-005Univ.dmg Security Update 2009-005 Server (Tiger PPC): http://support.apple.com/downloads/DL934/en_US/SecUpdSrvr2009-005PPC.dmg Mac OS X Server v10.6.1 Update: http://support.apple.com/downloads/DL929/en_US/MacOSXServerUpd10.6.1.dmg Security Update 2009-005 Server (Leopard): http://support.apple.com/downloads/DL936/en_US/SecUpdSrvr2009-005.dmg Security Update 2009-005 (Leopard): http://support.apple.com/downloads/DL935/en_US/SecUpd2009-005.dmg Mac OS X v10.6.1 Update: http://support.apple.com/downloads/DL930/en_US/MacOSXUpd10.6.1.dmg PROVIDED AND/OR DISCOVERED BY: 1, 2, 4, 8, 10-12, 16) Reported by the vendor. 5) The vendor credits Will Dormann of CERT/CC. 6) The vendor credits Will Drewry of Google. 15) The vendor credits J. David Hester of LCG Systems National Institutes of Health. ORIGINAL ADVISORY: http://support.apple.com/kb/HT3864 http://support.apple.com/kb/HT3865 OTHER REFERENCES: SA30134: http://secunia.com/advisories/30134/ SA34081: http://secunia.com/advisories/34081/ SA34481: http://secunia.com/advisories/34481/ SA34566: http://secunia.com/advisories/34566/ SA34612: http://secunia.com/advisories/34612/ SA35948: http://secunia.com/advisories/35948/ SA36269: http://secunia.com/advisories/36269/ ---------------------------------------------------------------------- About: This Advisory was delivered by Secunia as a free service to help everybody keeping their systems up to date against the latest vulnerabilities. Subscribe: http://secunia.com/advisories/secunia_security_advisories/ Definitions: (Criticality, Where etc.) http://secunia.com/advisories/about_secunia_advisories/ Please Note: Secunia recommends that you verify all advisories you receive by clicking the link. Secunia NEVER sends attached files with advisories. Secunia does not advise people to install third party patches, only use those supplied by the vendor. ---------------------------------------------------------------------- Unsubscribe: Secunia Security Advisories http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org ----------------------------------------------------------------------

Trust: 2.16

sources: NVD: CVE-2009-2811 // JVNDB: JVNDB-2009-002136 // BID: 36360 // VULHUB: VHN-40257 // VULMON: CVE-2009-2811 // PACKETSTORM: 81208

AFFECTED PRODUCTS

vendor:applemodel:mac os xscope:eqversion:10.5.8

Trust: 1.6

vendor:applemodel:mac os x serverscope:eqversion:10.5.8

Trust: 1.6

vendor:applemodel:mac os xscope:eqversion:v10.5.8

Trust: 0.8

vendor:applemodel:mac os x serverscope:eqversion:v10.5.8

Trust: 0.8

vendor:applemodel:mac os serverscope:eqversion:x10.5.8

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x10.5.7

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x10.5.6

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x10.5.5

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x10.5.4

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x10.5.3

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x10.5.2

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x10.5.1

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x10.5

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.5.8

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.5.7

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.5.6

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.5.5

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.5.4

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.5.3

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.5.2

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.5.1

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.5

Trust: 0.3

sources: BID: 36360 // JVNDB: JVNDB-2009-002136 // CNNVD: CNNVD-200909-279 // NVD: CVE-2009-2811

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2009-2811
value: MEDIUM

Trust: 1.0

NVD: CVE-2009-2811
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-200909-279
value: MEDIUM

Trust: 0.6

VULHUB: VHN-40257
value: MEDIUM

Trust: 0.1

VULMON: CVE-2009-2811
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2009-2811
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:M/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.6
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

VULHUB: VHN-40257
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:M/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.6
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-40257 // VULMON: CVE-2009-2811 // JVNDB: JVNDB-2009-002136 // CNNVD: CNNVD-200909-279 // NVD: CVE-2009-2811

PROBLEMTYPE DATA

problemtype:CWE-94

Trust: 1.9

sources: VULHUB: VHN-40257 // JVNDB: JVNDB-2009-002136 // NVD: CVE-2009-2811

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200909-279

TYPE

code injection

Trust: 0.6

sources: CNNVD: CNNVD-200909-279

CONFIGURATIONS

sources: JVNDB: JVNDB-2009-002136

PATCH

title:HT3865url:http://support.apple.com/kb/HT3865

Trust: 0.8

title:HT3865url:http://support.apple.com/kb/HT3865?viewlocale=ja_JP

Trust: 0.8

title:The Registerurl:https://www.theregister.co.uk/2021/09/22/macos_rce_flaw/

Trust: 0.1

sources: VULMON: CVE-2009-2811 // JVNDB: JVNDB-2009-002136

EXTERNAL IDS

db:NVDid:CVE-2009-2811

Trust: 2.9

db:SECUNIAid:36701

Trust: 2.7

db:BIDid:36360

Trust: 1.5

db:OSVDBid:57953

Trust: 1.2

db:JVNDBid:JVNDB-2009-002136

Trust: 0.8

db:CNNVDid:CNNVD-200909-279

Trust: 0.7

db:APPLEid:APPLE-SA-2009-09-10-2

Trust: 0.6

db:VULHUBid:VHN-40257

Trust: 0.1

db:VULMONid:CVE-2009-2811

Trust: 0.1

db:PACKETSTORMid:81208

Trust: 0.1

sources: VULHUB: VHN-40257 // VULMON: CVE-2009-2811 // BID: 36360 // JVNDB: JVNDB-2009-002136 // PACKETSTORM: 81208 // CNNVD: CNNVD-200909-279 // NVD: CVE-2009-2811

REFERENCES

url:http://secunia.com/advisories/36701

Trust: 2.6

url:http://support.apple.com/kb/ht3865

Trust: 1.9

url:http://lists.apple.com/archives/security-announce/2009/sep/msg00004.html

Trust: 1.8

url:http://www.securityfocus.com/bid/36360

Trust: 1.3

url:http://osvdb.org/57953

Trust: 1.2

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/53171

Trust: 1.2

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2009-2811

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2009-2811

Trust: 0.8

url:http://www.apple.com/macosx/

Trust: 0.3

url:https://cwe.mitre.org/data/definitions/94.html

Trust: 0.1

url:https://www.theregister.co.uk/2021/09/22/macos_rce_flaw/

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

url:http://secunia.com/advisories/35948/

Trust: 0.1

url:http://support.apple.com/downloads/dl936/en_us/secupdsrvr2009-005.dmg

Trust: 0.1

url:http://support.apple.com/downloads/dl933/en_us/secupdsrvr2009-005univ.dmg

Trust: 0.1

url:http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org

Trust: 0.1

url:http://secunia.com/advisories/34481/

Trust: 0.1

url:http://secunia.com/advisories/about_secunia_advisories/

Trust: 0.1

url:http://support.apple.com/downloads/dl932/en_us/secupd2009-005intel.dmg

Trust: 0.1

url:http://secunia.com/advisories/36269/

Trust: 0.1

url:http://secunia.com/advisories/secunia_security_advisories/

Trust: 0.1

url:http://secunia.com/advisories/business_solutions/

Trust: 0.1

url:http://support.apple.com/kb/ht3864

Trust: 0.1

url:http://support.apple.com/downloads/dl930/en_us/macosxupd10.6.1.dmg

Trust: 0.1

url:http://secunia.com/advisories/34566/

Trust: 0.1

url:http://support.apple.com/downloads/dl935/en_us/secupd2009-005.dmg

Trust: 0.1

url:http://secunia.com/advisories/36701/

Trust: 0.1

url:http://support.apple.com/downloads/dl934/en_us/secupdsrvr2009-005ppc.dmg

Trust: 0.1

url:http://support.apple.com/downloads/dl931/en_us/secupd2009-005ppc.dmg

Trust: 0.1

url:http://secunia.com/advisories/34081/

Trust: 0.1

url:http://secunia.com/advisories/34612/

Trust: 0.1

url:http://secunia.com/advisories/30134/

Trust: 0.1

url:http://support.apple.com/downloads/dl929/en_us/macosxserverupd10.6.1.dmg

Trust: 0.1

sources: VULHUB: VHN-40257 // VULMON: CVE-2009-2811 // BID: 36360 // JVNDB: JVNDB-2009-002136 // PACKETSTORM: 81208 // CNNVD: CNNVD-200909-279 // NVD: CVE-2009-2811

CREDITS

J. David Hester

Trust: 0.6

sources: CNNVD: CNNVD-200909-279

SOURCES

db:VULHUBid:VHN-40257
db:VULMONid:CVE-2009-2811
db:BIDid:36360
db:JVNDBid:JVNDB-2009-002136
db:PACKETSTORMid:81208
db:CNNVDid:CNNVD-200909-279
db:NVDid:CVE-2009-2811

LAST UPDATE DATE

2025-04-10T21:56:35.215000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-40257date:2017-08-17T00:00:00
db:VULMONid:CVE-2009-2811date:2017-08-17T00:00:00
db:BIDid:36360date:2009-09-11T16:32:00
db:JVNDBid:JVNDB-2009-002136date:2009-10-23T00:00:00
db:CNNVDid:CNNVD-200909-279date:2009-09-15T00:00:00
db:NVDid:CVE-2009-2811date:2025-04-09T00:30:58.490

SOURCES RELEASE DATE

db:VULHUBid:VHN-40257date:2009-09-14T00:00:00
db:VULMONid:CVE-2009-2811date:2009-09-14T00:00:00
db:BIDid:36360date:2009-09-10T00:00:00
db:JVNDBid:JVNDB-2009-002136date:2009-10-23T00:00:00
db:PACKETSTORMid:81208date:2009-09-11T14:30:33
db:CNNVDid:CNNVD-200909-279date:2009-09-14T00:00:00
db:NVDid:CVE-2009-2811date:2009-09-14T16:30:00.407