VARIoT IoT vulnerabilities database

Affected products: vendor, model and version
CWE format is 'CWE-number'. Threat type can be: remote or local
Look up free text in title and description

VAR-201209-0373 CVE-2012-3734 Apple iOS 6 Less than Office Viewer In Data Protection Vulnerabilities that are bypassed by level or encryption CVSS V2: 1.9
CVSS V3: -
Severity: LOW
Office Viewer in Apple iOS before 6 writes cleartext document data to a temporary file, which might allow local users to bypass a document's intended (1) Data Protection level or (2) encryption state by reading the temporary content. Apple iOS for the iPhone, the iPod touch, and the iPad is prone to a local information-disclosure vulnerability. Local attackers can leverage this issue to gain access to sensitive information. Information obtained may aid in further attacks. Note: This issue was previously discussed in BID 55612 (Apple iPhone/iPad/iPod touch Prior to iOS 6 Multiple Vulnerabilities) but has been given its own record to better document it. Apple iOS is an operating system developed by Apple (Apple) for mobile devices
VAR-201209-0374 CVE-2012-3735 Apple iOS 6 Vulnerabilities that allow you to view third-party applications used in the implementation of less than passcode lock CVSS V2: 2.1
CVSS V3: -
Severity: LOW
The Passcode Lock implementation in Apple iOS before 6 does not properly interact with the "Slide to Power Off" feature, which allows physically proximate attackers to see the most recently used third-party app by watching the device's screen. Apple iOS for the iPhone, the iPod touch, and the iPad is prone to a security weakness. An attacker with physical access to the affected device can exploit this issue to access user information. NOTE: This issue was previously discussed in BID 55612 (Apple iPhone/iPad/iPod touch Prior to iOS 6 Multiple Vulnerabilities) but has been given its own record to better document it. Apple iOS is an operating system developed by Apple (Apple) for mobile devices
VAR-201209-0371 CVE-2012-3732 Apple iOS Forgery of signed content in email CVSS V2: 6.4
CVSS V3: -
Severity: MEDIUM
Mail in Apple iOS before 6 uses an S/MIME message's From address as the displayed sender address, which allows remote attackers to spoof signed content via an e-mail message in which the From field does not match the signer's identity. Apple iOS for the iPhone, the iPod touch, and the iPad is prone to a spoofing vulnerability that affects the 'Mail' component. Note: This issue was previously discussed in BID 55612 (Apple iPhone/iPad/iPod touch Prior to iOS 6 Multiple Vulnerabilities) but has been given its own record to better document it. Apple iOS is an operating system developed by Apple (Apple) for mobile devices. The vulnerability stems from the use of the sender address of S/MIME messages to display the sender's address
VAR-201209-0370 CVE-2012-3731 Apple iOS Vulnerabilities that can bypass passcode requests in email CVSS V2: 2.1
CVSS V3: -
Severity: LOW
Mail in Apple iOS before 6 does not properly implement the Data Protection feature for e-mail attachments, which allows physically proximate attackers to bypass an intended passcode requirement via unspecified vectors. Apple iOS for the iPhone, the iPod touch, and the iPad is prone to a security-bypass vulnerability. This may aid in further attacks. NOTE: This issue was previously discussed in BID 55612 (Apple iPhone/iPad/iPod touch Prior to iOS 6 Multiple Vulnerabilities) but has been given its own record to better document it. Apple iOS is an operating system developed by Apple (Apple) for mobile devices. A proximity attacker could exploit this vulnerability to bypass specially crafted password requirements via an unidentified vector
VAR-201209-0372 CVE-2012-3733 Apple iOS 6 Vulnerabilities that can capture important information in messages less than CVSS V2: 4.3
CVSS V3: -
Severity: MEDIUM
Messages in Apple iOS before 6, when multiple iMessage e-mail addresses are configured, does not ensure that a reply's sender address matches the recipient address of the original message, which allows remote attackers to obtain potentially sensitive information about alternate e-mail addresses in opportunistic circumstances by reading a reply. TheBy reading the reply email, a third party may obtain important information about other email addresses. Apple iOS for the iPhone, the iPod touch, and the iPad is prone to an information-disclosure vulnerability. Attackers can leverage this issue to gain access to sensitive information. Information obtained may aid in further attacks. Note: This issue was previously discussed in BID 55612 (Apple iPhone/iPad/iPod touch Prior to iOS 6 Multiple Vulnerabilities) but has been given its own record to better document it. Apple iOS is an operating system developed by Apple (Apple) for mobile devices
VAR-201209-0369 CVE-2012-3730 Apple iOS Forged file attachment vulnerability CVSS V2: 4.3
CVSS V3: -
Severity: MEDIUM
Mail in Apple iOS before 6 does not properly handle reuse of Content-ID header values, which allows remote attackers to spoof attachments via a header value that was also used in a previous e-mail message, as demonstrated by a message from a different sender. Apple iOS for the iPhone, the iPod touch, and the iPad is prone to a security-bypass vulnerability. An attacker can exploit this issue to bypass certain security restrictions by spoofing email attachments, allowing the attacker to perform malicious activities. Other attacks may also be possible. Note: This issue was previously discussed in BID 55612 (Apple iPhone/iPad/iPod touch Prior to iOS 6 Multiple Vulnerabilities) but has been given its own record to better document it. Apple iOS is an operating system developed by Apple (Apple) for mobile devices
VAR-201209-0367 CVE-2012-3728 Apple iOS Privileged vulnerability in Kernel CVSS V2: 6.9
CVSS V3: -
Severity: MEDIUM
The kernel in Apple iOS before 6 dereferences invalid pointers during the handling of packet-filter data structures, which allows local users to gain privileges via a crafted program that makes packet-filter ioctl calls. Apple iOS for the iPhone, the iPod touch, andthe iPad is prone to a local privilege-escalation vulnerability that affects the kernel. Local attackers can exploit this issue to alter kernel memory and execute arbitrary code with system-level privileges. Successfully exploiting this issue can allow attackers to elevate privileges, leading to a complete compromise of the device. This issue is fixed in Apple iOS 6 version. NOTE: This issue was previously discussed in BID 55612 (Apple iPhone/iPad/iPod touch Prior to iOS 6 Multiple Vulnerabilities) but has been given its own record to better document it
VAR-201209-0368 CVE-2012-3729 Apple iOS Vulnerabilities in which important information is obtained in the kernel CVSS V2: 1.9
CVSS V3: -
Severity: LOW
The Berkeley Packet Filter (BPF) interpreter implementation in the kernel in Apple iOS before 6 accesses uninitialized memory locations, which allows local users to obtain sensitive information about the layout of kernel memory via a crafted program that uses a BPF interface. Apple iOS for the iPhone, the iPod touch, and the iPad is prone to an information-disclosure vulnerability. An attacker can exploit this issue to view content from the kernel memory. This may allow the attacker to obtain sensitive information or aid in further attacks. Note: This issue was previously discussed in BID 55612 (Apple iPhone/iPad/iPod touch Prior to iOS 6 Multiple Vulnerabilities) but has been given its own record to better document it. Apple iOS is an operating system developed by Apple (Apple) for mobile devices. The vulnerability stems from accessing uninitialized memory locations
VAR-201209-0366 CVE-2012-3727 Apple iOS of IPsec Component buffer overflow vulnerability CVSS V2: 6.8
CVSS V3: -
Severity: MEDIUM
Buffer overflow in the IPsec component in Apple iOS before 6 allows remote attackers to execute arbitrary code via a crafted racoon configuration file. Apple iOS for the iPhone, the iPod touch, and the iPad is prone to a buffer-overflow vulnerability. Successfully exploiting this issue may allow attackers to execute arbitrary code in the context of the affected application. Failed exploit attempts may cause denial-of-service conditions. NOTE: This issue was previously discussed in BID 55612 (Apple iPhone/iPad/iPod touch Prior to iOS 6 Multiple Vulnerabilities) but has been given its own record to better document it. Apple iOS is an operating system developed by Apple (Apple) for mobile devices
VAR-201209-0363 CVE-2012-3724 Apple iOS of CFNetwork Vulnerability in which important information is obtained CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
CFNetwork in Apple iOS before 6 does not properly identify the host portion of a URL, which allows remote attackers to obtain sensitive information by leveraging the construction of an HTTP request with an incorrect hostname derived from a malformed URL. Apple iOS for the iPhone, the iPod touch, and the iPad is prone to an information-disclosure vulnerability. Attackers can leverage this issue to gain access to sensitive information. Information obtained may aid in further attacks. Note: This issue was previously discussed in BID 55612 (Apple iPhone/iPad/iPod touch Prior to iOS 6 Multiple Vulnerabilities) but has been given its own record to better document it. Apple iOS is an operating system developed by Apple (Apple) for mobile devices. A vulnerability exists in CFNetwork in versions prior to Apple iOS 6 due to partial URLs not correctly identifying hosts
VAR-201209-0364 CVE-2012-3725 Apple iOS of DHCP Vulnerabilities that can capture important information in components CVSS V2: 3.3
CVSS V3: -
Severity: LOW
The DNAv4 protocol implementation in the DHCP component in Apple iOS before 6 sends Wi-Fi packets containing a MAC address of a host on a previously used network, which might allow remote attackers to obtain sensitive information about previous device locations by sniffing an unencrypted Wi-Fi network for these packets. Apple iOS of DHCP In the component DNAv4 The protocol is implemented by the host on the network used immediately before. Successfully exploiting this issue will allow attackers to determine networks a device has previously accessed. Note: This issue was previously discussed in BID 55612 (Apple iPhone/iPad/iPod touch Prior to iOS 6 Multiple Vulnerabilities) but has been given its own record to better document it. Apple iOS is an operating system developed by Apple (Apple) for mobile devices. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 APPLE-SA-2012-09-24-1 Apple TV 5.1 Apple TV 5.1 is now available and addresses the following: Apple TV Available for: Apple TV 2nd generation and later Impact: Viewing a maliciously crafted movie file may lead to an unexpected application termination or arbitrary code execution Description: An uninitialized memory access existed in the handling of Sorenson encoded movie files. This issue was addressed through improved memory initialization. This issue was addressed by disabling DNAv4 on unencrypted Wi-Fi networks CVE-ID CVE-2012-3725 : Mark Wuergler of Immunity, Inc. Apple TV Available for: Apple TV 2nd generation and later Impact: Viewing a maliciously crafted TIFF file may lead to an unexpected application termination or arbitrary code execution Description: A buffer overflow existed in libtiff's handling of ThunderScan encoded TIFF images. This issue was addressed by updating libtiff to version 3.9.5. CVE-ID CVE-2011-1167 Apple TV Available for: Apple TV 2nd generation and later Impact: Viewing a maliciously crafted PNG image may lead to an unexpected application termination or arbitrary code execution Description: Multiple memory corruption issues existed in libpng's handling of PNG images. These issues were addressed through improved validation of PNG images. CVE-ID CVE-2011-3026 : Juri Aedla CVE-2011-3048 CVE-2011-3328 Apple TV Available for: Apple TV 2nd generation and later Impact: Viewing a maliciously crafted JPEG image may lead to an unexpected application termination or arbitrary code execution Description: A double free issue existed in ImageIO's handling of JPEG images. This issue was addressed through improved memory management. CVE-ID CVE-2012-3726 : Phil of PKJE Consulting Apple TV Available for: Apple TV 2nd generation and later Impact: Viewing a maliciously crafted TIFF image may lead to an unexpected application termination or arbitrary code execution Description: An integer overflow issue existed in libTIFF's handling of TIFF images. This issue was addressed through improved validation of TIFF images. This issue does not affect OS X Mountain Lion systems. CVE-ID CVE-2012-1173 Apple TV Available for: Apple TV 2nd generation and later Impact: Applications that use ICU may be vulnerable to an unexpected application termination or arbitrary code execution Description: A stack buffer overflow existed in the handling of ICU locale IDs. This issue was addressed through improved bounds checking. CVE-ID CVE-2011-4599 Apple TV Available for: Apple TV 2nd generation and later Impact: An attacker with a privileged network position may cause an unexpected application termination or arbitrary code execution Description: Multiple vulnerabilities existed in libxml, the most serious of which may lead to an unexpected application termination or arbitrary code execution. These issues were addressed by applying the relevant upstream patches. CVE-ID CVE-2011-1944 : Chris Evans of Google Chrome Security Team CVE-2011-2821 : Yang Dingning of NCNIPC, Graduate University of Chinese Academy of Sciences CVE-2011-2834 : Yang Dingning of NCNIPC, Graduate University of Chinese Academy of Sciences CVE-2011-3919 : Juri Aedla Apple TV Available for: Apple TV 2nd generation and later Impact: An attacker with a privileged network position may cause an unexpected application termination or arbitrary code execution Description: Multiple memory corruption issues existed in JavaScriptCore. These issues were addressed through improved memory handling. CVE-ID CVE-2012-0682 : Apple Product Security CVE-2012-0683 : Dave Mandelin of Mozilla CVE-2012-3589 : Dave Mandelin of Mozilla CVE-2012-3590 : Apple Product Security CVE-2012-3591 : Apple Product Security CVE-2012-3592 : Apple Product Security CVE-2012-3678 : Apple Product Security CVE-2012-3679 : Chris Leary of Mozilla Installation note: Apple TV will periodically check for software updates. Alternatively, you may manually check for software updates by selecting "Settings -> General -> Update Software". To check the current version of software, select "Settings -> General -> About". Information will also be posted to the Apple Security Updates web site: http://support.apple.com/kb/HT1222 This message is signed with Apple's Product Security PGP key, and details are available at: https://www.apple.com/support/security/pgp/ -----BEGIN PGP SIGNATURE----- Version: GnuPG/MacGPG2 v2.0.17 (Darwin) Comment: GPGTools - http://gpgtools.org iQIcBAEBAgAGBQJQXO50AAoJEPefwLHPlZEwc40P/AmBKys+PAsdT8gGrSpOY1B9 8h+Y0xdE+Hmesq9D4p6wvdY/lR+zMqtSwT6amNImYCIaRmm1P8+r8n31be52TYlg 7GqEAZbDtFztHwIISC8Khf8dMvWSrLhzRa7X/cxlIgRKmoXFnqJZzYcUov/M9Uw8 KwejQnztmAx7srHnZCNI+dxFqAC7hPoegnDnlVPx1DkwKDjt8q9xD3PGQyiGWWkI wqUEWvMGWr65CFyA7R0hDqKuNCowWn2cKP1UhIoEur5yRmc4aQVtOnHhJ8k9mdoO +58JC/y8lCtqGUyEL2Ar0FmIcRX/GJf+/isKOtmHx0JuEhH5beQ6s9FxU5eNR9DH EVPmVXowY9wMvKxwHFU3jwq8kQ3+IYC+7KA6lScb5mXO5mC5dbJPLp7uJto7+VtI atgQmvzdB8G562wpwTPuA4UQWWr0i6WWl8zkfgkRHO+cXyN683rkBP/vVEo9FipR YkQ10RsXqYDRXBcRywmTZZwQy6txMtV9D2bnk1uukQHBsZh30/mEpcmZbo6CO3s3 mnOtu5D2OQsNt4MqbviUkEgdc9JIJnqAOo+9YguDCEu6Rd7unbKB3RpmD+A3OJnR GhEa2Gqyvm/ozfb2D4L01y4UQo7dMLw+t/FOZXkrpdLlWn2LANWvXDCPSzIFCKoN cXF+ij425pfY+d7Iekz3 =PSL+ -----END PGP SIGNATURE-----
VAR-201209-0365 CVE-2012-3726 Apple iOS of ImageIO Memory double free vulnerability CVSS V2: 6.8
CVSS V3: -
Severity: MEDIUM
Double free vulnerability in ImageIO in Apple iOS before 6 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted JPEG image. Apple iOS for the iPhone, the iPod touch, and the iPad is prone to remote code-execution vulnerability. Successfully exploiting this issue will allow the attacker to execute arbitrary code in the context of the affected application. Failed exploit attempts may result in a denial-of-service condition. Note: This issue was previously discussed in BID 55612 (Apple iPhone/iPad/iPod touch Prior to iOS 6 Multiple Vulnerabilities) but has been given its own record to better document it. Apple iOS is an operating system developed by Apple (Apple) for mobile devices. A double free vulnerability exists in ImageIO in versions prior to Apple iOS 6. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 APPLE-SA-2012-09-24-1 Apple TV 5.1 Apple TV 5.1 is now available and addresses the following: Apple TV Available for: Apple TV 2nd generation and later Impact: Viewing a maliciously crafted movie file may lead to an unexpected application termination or arbitrary code execution Description: An uninitialized memory access existed in the handling of Sorenson encoded movie files. This issue was addressed through improved memory initialization. CVE-ID CVE-2012-3722 : Will Dormann of the CERT/CC Apple TV Available for: Apple TV 2nd generation and later Impact: A malicious Wi-Fi network may be able to determine networks a device has previously accessed Description: Upon connecting to a Wi-Fi network, iOS may broadcast MAC addresses of previously accessed networks per the DNAv4 protocol. This issue was addressed by disabling DNAv4 on unencrypted Wi-Fi networks CVE-ID CVE-2012-3725 : Mark Wuergler of Immunity, Inc. Apple TV Available for: Apple TV 2nd generation and later Impact: Viewing a maliciously crafted TIFF file may lead to an unexpected application termination or arbitrary code execution Description: A buffer overflow existed in libtiff's handling of ThunderScan encoded TIFF images. This issue was addressed by updating libtiff to version 3.9.5. CVE-ID CVE-2011-1167 Apple TV Available for: Apple TV 2nd generation and later Impact: Viewing a maliciously crafted PNG image may lead to an unexpected application termination or arbitrary code execution Description: Multiple memory corruption issues existed in libpng's handling of PNG images. These issues were addressed through improved validation of PNG images. This issue was addressed through improved memory management. CVE-ID CVE-2012-3726 : Phil of PKJE Consulting Apple TV Available for: Apple TV 2nd generation and later Impact: Viewing a maliciously crafted TIFF image may lead to an unexpected application termination or arbitrary code execution Description: An integer overflow issue existed in libTIFF's handling of TIFF images. This issue was addressed through improved validation of TIFF images. This issue does not affect OS X Mountain Lion systems. CVE-ID CVE-2012-1173 Apple TV Available for: Apple TV 2nd generation and later Impact: Applications that use ICU may be vulnerable to an unexpected application termination or arbitrary code execution Description: A stack buffer overflow existed in the handling of ICU locale IDs. This issue was addressed through improved bounds checking. These issues were addressed by applying the relevant upstream patches. CVE-ID CVE-2011-1944 : Chris Evans of Google Chrome Security Team CVE-2011-2821 : Yang Dingning of NCNIPC, Graduate University of Chinese Academy of Sciences CVE-2011-2834 : Yang Dingning of NCNIPC, Graduate University of Chinese Academy of Sciences CVE-2011-3919 : Juri Aedla Apple TV Available for: Apple TV 2nd generation and later Impact: An attacker with a privileged network position may cause an unexpected application termination or arbitrary code execution Description: Multiple memory corruption issues existed in JavaScriptCore. These issues were addressed through improved memory handling. CVE-ID CVE-2012-0682 : Apple Product Security CVE-2012-0683 : Dave Mandelin of Mozilla CVE-2012-3589 : Dave Mandelin of Mozilla CVE-2012-3590 : Apple Product Security CVE-2012-3591 : Apple Product Security CVE-2012-3592 : Apple Product Security CVE-2012-3678 : Apple Product Security CVE-2012-3679 : Chris Leary of Mozilla Installation note: Apple TV will periodically check for software updates. Alternatively, you may manually check for software updates by selecting "Settings -> General -> Update Software". To check the current version of software, select "Settings -> General -> About". Information will also be posted to the Apple Security Updates web site: http://support.apple.com/kb/HT1222 This message is signed with Apple's Product Security PGP key, and details are available at: https://www.apple.com/support/security/pgp/ -----BEGIN PGP SIGNATURE----- Version: GnuPG/MacGPG2 v2.0.17 (Darwin) Comment: GPGTools - http://gpgtools.org iQIcBAEBAgAGBQJQXO50AAoJEPefwLHPlZEwc40P/AmBKys+PAsdT8gGrSpOY1B9 8h+Y0xdE+Hmesq9D4p6wvdY/lR+zMqtSwT6amNImYCIaRmm1P8+r8n31be52TYlg 7GqEAZbDtFztHwIISC8Khf8dMvWSrLhzRa7X/cxlIgRKmoXFnqJZzYcUov/M9Uw8 KwejQnztmAx7srHnZCNI+dxFqAC7hPoegnDnlVPx1DkwKDjt8q9xD3PGQyiGWWkI wqUEWvMGWr65CFyA7R0hDqKuNCowWn2cKP1UhIoEur5yRmc4aQVtOnHhJ8k9mdoO +58JC/y8lCtqGUyEL2Ar0FmIcRX/GJf+/isKOtmHx0JuEhH5beQ6s9FxU5eNR9DH EVPmVXowY9wMvKxwHFU3jwq8kQ3+IYC+7KA6lScb5mXO5mC5dbJPLp7uJto7+VtI atgQmvzdB8G562wpwTPuA4UQWWr0i6WWl8zkfgkRHO+cXyN683rkBP/vVEo9FipR YkQ10RsXqYDRXBcRywmTZZwQy6txMtV9D2bnk1uukQHBsZh30/mEpcmZbo6CO3s3 mnOtu5D2OQsNt4MqbviUkEgdc9JIJnqAOo+9YguDCEu6Rd7unbKB3RpmD+A3OJnR GhEa2Gqyvm/ozfb2D4L01y4UQo7dMLw+t/FOZXkrpdLlWn2LANWvXDCPSzIFCKoN cXF+ij425pfY+d7Iekz3 =PSL+ -----END PGP SIGNATURE-----
VAR-201209-0362 CVE-2012-3723 Apple Mac OS X Vulnerable to arbitrary code execution CVSS V2: 4.6
CVSS V3: -
Severity: MEDIUM
Apple Mac OS X before 10.7.5 does not properly handle the bNbrPorts field of a USB hub descriptor, which allows physically proximate attackers to execute arbitrary code or cause a denial of service (memory corruption and system crash) by attaching a USB device. Apple Mac OS X is prone to a local memory-corruption vulnerability. Successful exploits may allow attackers to execute arbitrary code within the context of the affected application. Failed attacks may cause a denial-of-service condition. NOTE: This issue was previously discussed in BID 55623 (Apple Mac OS X Security Update 2012-004 Multiple Security Vulnerabilities) but has been given its own record to better document it. ---------------------------------------------------------------------- The final version of the CSI 6.0 has been released. Find out why this is not just another Patch Management solution: http://secunia.com/blog/325/ ---------------------------------------------------------------------- TITLE: Apple Mac OS X Multiple Vulnerabilities SECUNIA ADVISORY ID: SA50628 VERIFY ADVISORY: Secunia.com http://secunia.com/advisories/50628/ Customer Area (Credentials Required) https://ca.secunia.com/?page=viewadvisory&vuln_id=50628 RELEASE DATE: 2012-09-20 DISCUSS ADVISORY: http://secunia.com/advisories/50628/#comments AVAILABLE ON SITE AND IN CUSTOMER AREA: * Last Update * Popularity * Comments * Criticality Level * Impact * Where * Solution Status * Operating System / Software * CVE Reference(s) http://secunia.com/advisories/50628/ ONLY AVAILABLE IN CUSTOMER AREA: * Authentication Level * Report Reliability * Secunia PoC * Secunia Analysis * Systems Affected * Approve Distribution * Remediation Status * Secunia CVSS Score * CVSS https://ca.secunia.com/?page=viewadvisory&vuln_id=50628 ONLY AVAILABLE WITH SECUNIA CSI AND SECUNIA PSI: * AUTOMATED SCANNING http://secunia.com/vulnerability_scanning/personal/ http://secunia.com/vulnerability_scanning/corporate/wsus_sccm_3rd_third_party_patching/ DESCRIPTION: Apple has issued a security update for Mac OS X, which fixes multiple vulnerabilities. 1) Various vulnerabilities exist in the bundled version of Apache. For more information: SA46288 SA45793 SA46987 SA47779 SA47410 2) An assertion error in BIND when handling DNS records can be exploited to cause a DoS (Denial of Service). For more information: SA46887 3) An error in BIND can be exploited to disclose potentially sensitive information or cause a DoS. For more information: SA49338 4) An error in the CoreText component when handling text glyphs can be exploited to cause a buffer overflow and potentially compromise an application using the component. 5) An error in the DirectoryService Proxy can be exploited to cause a buffer overflow. 6) Errors in the ImageIO component when parsing PNG images can be exploited to corrupt memory. For more information: SA48026 SA48587 7) An integer overflow error in the ImageIO component when parsing TIFF images can be exploited to cause a buffer overflow. For more information: SA48684#1 8) A previous fix did not properly address an error in the Installer component that allowed users to obtain account information. The original fix ensured that passwords were not recorded to the system log, but did not remove the old system log entries containing passwords. This is related to: SA49039#1 9) An error in International Components for Unicode (ICU) when handling ICU locale IDs can be exploited to cause a stack-based buffer overflow. For more information: SA47146 10) A logic error in the kernel when handling debug system calls can be exploited by a malicious program to bypass sandbox restrictions. For more information: SA48288#3 11) An error in the LoginWindow component can be exploited by local users to obtain other users' login passwords. 12) An input validation error in Mail can be exploited to execute web plugins when viewing an e-mail message. 13) An error in Mobile Accounts can be exploited by a user with access to the contents of a mobile account to obtain the account password. 14) Multiple errors exist in the bundled version of PHP. For more information: SA49014 SA44335 15) An authentication error in Profile Manager Device Management private interface can be exploited to enumerate managed devices. 16) Various errors exist in the bundled versions of QuickLook and QuickTime. For more information: SA47447 17) An uninitialised memory access error exists in QuickTime when viewing Sorenson-encoded movie files. 18) An error in Ruby may allow decryption of SSL-protected data when a cipher suite uses a block cipher in CBC mode. 19) An error in the USB component can be exploited to corrupt memory by attaching a malicious USB device. SOLUTION: Update to version 10.8.2 or 10.7.5 or apply Security Update 2012-004. PROVIDED AND/OR DISCOVERED BY: The vendor credits: 4) Jesse Ruderman, Mozilla Corporation 5) aazubel via ZDI 11) An anonymous person 12, 17) Will Dormann, CERT/CC 13) Harald Wagener, Google 15) Derick Cassidy, XEquals Corporation 19) Andy Davis, NGS Secure ORIGINAL ADVISORY: Apple: http://support.apple.com/kb/HT5501 OTHER REFERENCES: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ DEEP LINKS: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ EXTENDED DESCRIPTION: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ EXTENDED SOLUTION: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ EXPLOIT: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ ---------------------------------------------------------------------- About: This Advisory was delivered by Secunia as a free service to help private users keeping their systems up to date against the latest vulnerabilities. Subscribe: http://secunia.com/advisories/secunia_security_advisories/ Definitions: (Criticality, Where etc.) http://secunia.com/advisories/about_secunia_advisories/ Please Note: Secunia recommends that you verify all advisories you receive by clicking the link. Secunia NEVER sends attached files with advisories. Secunia does not advise people to install third party patches, only use those supplied by the vendor. ---------------------------------------------------------------------- Unsubscribe: Secunia Security Advisories http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org ----------------------------------------------------------------------
VAR-201209-0360 CVE-2012-3721 Apple Mac OS X of Profile Manager Vulnerability that enumerates managed devices CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Profile Manager in Apple Mac OS X before 10.7.5 does not properly perform authentication for the Device Management private interface, which allows attackers to enumerate managed devices via unspecified vectors. Attackers can exploit this issue to harvest valid device names, which may aid in further attacks. NOTE: This issue was previously discussed in BID 55623 (Apple Mac OS X Security Update 2012-004 Multiple Security Vulnerabilities) but has been given its own record to better document it. This issue is fixed in the following versions: Mac OS X 10.7.5 Mac OS X 10.8.2. ---------------------------------------------------------------------- The final version of the CSI 6.0 has been released. Find out why this is not just another Patch Management solution: http://secunia.com/blog/325/ ---------------------------------------------------------------------- TITLE: Apple Mac OS X Multiple Vulnerabilities SECUNIA ADVISORY ID: SA50628 VERIFY ADVISORY: Secunia.com http://secunia.com/advisories/50628/ Customer Area (Credentials Required) https://ca.secunia.com/?page=viewadvisory&vuln_id=50628 RELEASE DATE: 2012-09-20 DISCUSS ADVISORY: http://secunia.com/advisories/50628/#comments AVAILABLE ON SITE AND IN CUSTOMER AREA: * Last Update * Popularity * Comments * Criticality Level * Impact * Where * Solution Status * Operating System / Software * CVE Reference(s) http://secunia.com/advisories/50628/ ONLY AVAILABLE IN CUSTOMER AREA: * Authentication Level * Report Reliability * Secunia PoC * Secunia Analysis * Systems Affected * Approve Distribution * Remediation Status * Secunia CVSS Score * CVSS https://ca.secunia.com/?page=viewadvisory&vuln_id=50628 ONLY AVAILABLE WITH SECUNIA CSI AND SECUNIA PSI: * AUTOMATED SCANNING http://secunia.com/vulnerability_scanning/personal/ http://secunia.com/vulnerability_scanning/corporate/wsus_sccm_3rd_third_party_patching/ DESCRIPTION: Apple has issued a security update for Mac OS X, which fixes multiple vulnerabilities. 1) Various vulnerabilities exist in the bundled version of Apache. For more information: SA46288 SA45793 SA46987 SA47779 SA47410 2) An assertion error in BIND when handling DNS records can be exploited to cause a DoS (Denial of Service). For more information: SA46887 3) An error in BIND can be exploited to disclose potentially sensitive information or cause a DoS. For more information: SA49338 4) An error in the CoreText component when handling text glyphs can be exploited to cause a buffer overflow and potentially compromise an application using the component. 5) An error in the DirectoryService Proxy can be exploited to cause a buffer overflow. 6) Errors in the ImageIO component when parsing PNG images can be exploited to corrupt memory. For more information: SA48026 SA48587 7) An integer overflow error in the ImageIO component when parsing TIFF images can be exploited to cause a buffer overflow. For more information: SA48684#1 8) A previous fix did not properly address an error in the Installer component that allowed users to obtain account information. The original fix ensured that passwords were not recorded to the system log, but did not remove the old system log entries containing passwords. This is related to: SA49039#1 9) An error in International Components for Unicode (ICU) when handling ICU locale IDs can be exploited to cause a stack-based buffer overflow. For more information: SA47146 10) A logic error in the kernel when handling debug system calls can be exploited by a malicious program to bypass sandbox restrictions. For more information: SA48288#3 11) An error in the LoginWindow component can be exploited by local users to obtain other users' login passwords. 12) An input validation error in Mail can be exploited to execute web plugins when viewing an e-mail message. 13) An error in Mobile Accounts can be exploited by a user with access to the contents of a mobile account to obtain the account password. 14) Multiple errors exist in the bundled version of PHP. 16) Various errors exist in the bundled versions of QuickLook and QuickTime. For more information: SA47447 17) An uninitialised memory access error exists in QuickTime when viewing Sorenson-encoded movie files. 18) An error in Ruby may allow decryption of SSL-protected data when a cipher suite uses a block cipher in CBC mode. 19) An error in the USB component can be exploited to corrupt memory by attaching a malicious USB device. SOLUTION: Update to version 10.8.2 or 10.7.5 or apply Security Update 2012-004. PROVIDED AND/OR DISCOVERED BY: The vendor credits: 4) Jesse Ruderman, Mozilla Corporation 5) aazubel via ZDI 11) An anonymous person 12, 17) Will Dormann, CERT/CC 13) Harald Wagener, Google 15) Derick Cassidy, XEquals Corporation 19) Andy Davis, NGS Secure ORIGINAL ADVISORY: Apple: http://support.apple.com/kb/HT5501 OTHER REFERENCES: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ DEEP LINKS: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ EXTENDED DESCRIPTION: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ EXTENDED SOLUTION: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ EXPLOIT: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ ---------------------------------------------------------------------- About: This Advisory was delivered by Secunia as a free service to help private users keeping their systems up to date against the latest vulnerabilities. Subscribe: http://secunia.com/advisories/secunia_security_advisories/ Definitions: (Criticality, Where etc.) http://secunia.com/advisories/about_secunia_advisories/ Please Note: Secunia recommends that you verify all advisories you receive by clicking the link. Secunia NEVER sends attached files with advisories. Secunia does not advise people to install third party patches, only use those supplied by the vendor. ---------------------------------------------------------------------- Unsubscribe: Secunia Security Advisories http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org ----------------------------------------------------------------------
VAR-201209-0359 CVE-2012-3720 Apple Mac OS X Password identification vulnerability in mobile accounts CVSS V2: 4.3
CVSS V3: -
Severity: MEDIUM
Mobile Accounts in Apple Mac OS X before 10.7.5 and 10.8.x before 10.8.2 saves password hashes for external-account use even if external accounts are not enabled, which might allow remote attackers to determine passwords via unspecified access to a mobile account. Apple Mac OS X is prone to an information-disclosure vulnerability. Attackers can leverage this issue to gain access to sensitive information. Information obtained may aid in further attacks. The following versions are affected: Mac OS X 10.8 Mac OS X Server 10.8.1 NOTE: This issue was previously discussed in BID 55623 (Apple Mac OS X Security Update 2012-004 Multiple Security Vulnerabilities) but has been given its own record to better document it. ---------------------------------------------------------------------- The final version of the CSI 6.0 has been released. Find out why this is not just another Patch Management solution: http://secunia.com/blog/325/ ---------------------------------------------------------------------- TITLE: Apple Mac OS X Multiple Vulnerabilities SECUNIA ADVISORY ID: SA50628 VERIFY ADVISORY: Secunia.com http://secunia.com/advisories/50628/ Customer Area (Credentials Required) https://ca.secunia.com/?page=viewadvisory&vuln_id=50628 RELEASE DATE: 2012-09-20 DISCUSS ADVISORY: http://secunia.com/advisories/50628/#comments AVAILABLE ON SITE AND IN CUSTOMER AREA: * Last Update * Popularity * Comments * Criticality Level * Impact * Where * Solution Status * Operating System / Software * CVE Reference(s) http://secunia.com/advisories/50628/ ONLY AVAILABLE IN CUSTOMER AREA: * Authentication Level * Report Reliability * Secunia PoC * Secunia Analysis * Systems Affected * Approve Distribution * Remediation Status * Secunia CVSS Score * CVSS https://ca.secunia.com/?page=viewadvisory&vuln_id=50628 ONLY AVAILABLE WITH SECUNIA CSI AND SECUNIA PSI: * AUTOMATED SCANNING http://secunia.com/vulnerability_scanning/personal/ http://secunia.com/vulnerability_scanning/corporate/wsus_sccm_3rd_third_party_patching/ DESCRIPTION: Apple has issued a security update for Mac OS X, which fixes multiple vulnerabilities. 1) Various vulnerabilities exist in the bundled version of Apache. For more information: SA46288 SA45793 SA46987 SA47779 SA47410 2) An assertion error in BIND when handling DNS records can be exploited to cause a DoS (Denial of Service). For more information: SA46887 3) An error in BIND can be exploited to disclose potentially sensitive information or cause a DoS. For more information: SA49338 4) An error in the CoreText component when handling text glyphs can be exploited to cause a buffer overflow and potentially compromise an application using the component. 5) An error in the DirectoryService Proxy can be exploited to cause a buffer overflow. 6) Errors in the ImageIO component when parsing PNG images can be exploited to corrupt memory. For more information: SA48026 SA48587 7) An integer overflow error in the ImageIO component when parsing TIFF images can be exploited to cause a buffer overflow. For more information: SA48684#1 8) A previous fix did not properly address an error in the Installer component that allowed users to obtain account information. The original fix ensured that passwords were not recorded to the system log, but did not remove the old system log entries containing passwords. This is related to: SA49039#1 9) An error in International Components for Unicode (ICU) when handling ICU locale IDs can be exploited to cause a stack-based buffer overflow. For more information: SA47146 10) A logic error in the kernel when handling debug system calls can be exploited by a malicious program to bypass sandbox restrictions. For more information: SA48288#3 11) An error in the LoginWindow component can be exploited by local users to obtain other users' login passwords. 12) An input validation error in Mail can be exploited to execute web plugins when viewing an e-mail message. 14) Multiple errors exist in the bundled version of PHP. For more information: SA49014 SA44335 15) An authentication error in Profile Manager Device Management private interface can be exploited to enumerate managed devices. 16) Various errors exist in the bundled versions of QuickLook and QuickTime. For more information: SA47447 17) An uninitialised memory access error exists in QuickTime when viewing Sorenson-encoded movie files. 18) An error in Ruby may allow decryption of SSL-protected data when a cipher suite uses a block cipher in CBC mode. 19) An error in the USB component can be exploited to corrupt memory by attaching a malicious USB device. SOLUTION: Update to version 10.8.2 or 10.7.5 or apply Security Update 2012-004. PROVIDED AND/OR DISCOVERED BY: The vendor credits: 4) Jesse Ruderman, Mozilla Corporation 5) aazubel via ZDI 11) An anonymous person 12, 17) Will Dormann, CERT/CC 13) Harald Wagener, Google 15) Derick Cassidy, XEquals Corporation 19) Andy Davis, NGS Secure ORIGINAL ADVISORY: Apple: http://support.apple.com/kb/HT5501 OTHER REFERENCES: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ DEEP LINKS: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ EXTENDED DESCRIPTION: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ EXTENDED SOLUTION: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ EXPLOIT: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ ---------------------------------------------------------------------- About: This Advisory was delivered by Secunia as a free service to help private users keeping their systems up to date against the latest vulnerabilities. Subscribe: http://secunia.com/advisories/secunia_security_advisories/ Definitions: (Criticality, Where etc.) http://secunia.com/advisories/about_secunia_advisories/ Please Note: Secunia recommends that you verify all advisories you receive by clicking the link. Secunia NEVER sends attached files with advisories. Secunia does not advise people to install third party patches, only use those supplied by the vendor. ---------------------------------------------------------------------- Unsubscribe: Secunia Security Advisories http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org ----------------------------------------------------------------------
VAR-201209-0358 CVE-2012-3719 Apple Mac OS X Vulnerabilities in arbitrary plug-in code in email CVSS V2: 6.8
CVSS V3: -
Severity: MEDIUM
Mail in Apple Mac OS X before 10.7.5 does not properly handle embedded web plugins, which allows remote attackers to execute arbitrary plugin code via an e-mail message that triggers the loading of a third-party plugin. Apple Mac OS X is prone to an arbitrary code-execution vulnerability. Successfully exploiting this issue can allow attackers to execute arbitrary code in the context of the of the currently logged-in user. NOTE: This issue was previously discussed in BID 55623 (Apple Mac OS X Security Update 2012-004 Multiple Security Vulnerabilities) but has been given its own record to better document it. This issue is fixed in the following versions: Mac OS X 10.7.5 Mac OS X 10.8.2. ---------------------------------------------------------------------- The final version of the CSI 6.0 has been released. Find out why this is not just another Patch Management solution: http://secunia.com/blog/325/ ---------------------------------------------------------------------- TITLE: Apple Mac OS X Multiple Vulnerabilities SECUNIA ADVISORY ID: SA50628 VERIFY ADVISORY: Secunia.com http://secunia.com/advisories/50628/ Customer Area (Credentials Required) https://ca.secunia.com/?page=viewadvisory&vuln_id=50628 RELEASE DATE: 2012-09-20 DISCUSS ADVISORY: http://secunia.com/advisories/50628/#comments AVAILABLE ON SITE AND IN CUSTOMER AREA: * Last Update * Popularity * Comments * Criticality Level * Impact * Where * Solution Status * Operating System / Software * CVE Reference(s) http://secunia.com/advisories/50628/ ONLY AVAILABLE IN CUSTOMER AREA: * Authentication Level * Report Reliability * Secunia PoC * Secunia Analysis * Systems Affected * Approve Distribution * Remediation Status * Secunia CVSS Score * CVSS https://ca.secunia.com/?page=viewadvisory&vuln_id=50628 ONLY AVAILABLE WITH SECUNIA CSI AND SECUNIA PSI: * AUTOMATED SCANNING http://secunia.com/vulnerability_scanning/personal/ http://secunia.com/vulnerability_scanning/corporate/wsus_sccm_3rd_third_party_patching/ DESCRIPTION: Apple has issued a security update for Mac OS X, which fixes multiple vulnerabilities. 1) Various vulnerabilities exist in the bundled version of Apache. For more information: SA46288 SA45793 SA46987 SA47779 SA47410 2) An assertion error in BIND when handling DNS records can be exploited to cause a DoS (Denial of Service). For more information: SA46887 3) An error in BIND can be exploited to disclose potentially sensitive information or cause a DoS. For more information: SA49338 4) An error in the CoreText component when handling text glyphs can be exploited to cause a buffer overflow and potentially compromise an application using the component. 5) An error in the DirectoryService Proxy can be exploited to cause a buffer overflow. 6) Errors in the ImageIO component when parsing PNG images can be exploited to corrupt memory. For more information: SA48026 SA48587 7) An integer overflow error in the ImageIO component when parsing TIFF images can be exploited to cause a buffer overflow. For more information: SA48684#1 8) A previous fix did not properly address an error in the Installer component that allowed users to obtain account information. The original fix ensured that passwords were not recorded to the system log, but did not remove the old system log entries containing passwords. This is related to: SA49039#1 9) An error in International Components for Unicode (ICU) when handling ICU locale IDs can be exploited to cause a stack-based buffer overflow. For more information: SA47146 10) A logic error in the kernel when handling debug system calls can be exploited by a malicious program to bypass sandbox restrictions. For more information: SA48288#3 11) An error in the LoginWindow component can be exploited by local users to obtain other users' login passwords. 12) An input validation error in Mail can be exploited to execute web plugins when viewing an e-mail message. 13) An error in Mobile Accounts can be exploited by a user with access to the contents of a mobile account to obtain the account password. 14) Multiple errors exist in the bundled version of PHP. For more information: SA49014 SA44335 15) An authentication error in Profile Manager Device Management private interface can be exploited to enumerate managed devices. 16) Various errors exist in the bundled versions of QuickLook and QuickTime. For more information: SA47447 17) An uninitialised memory access error exists in QuickTime when viewing Sorenson-encoded movie files. 18) An error in Ruby may allow decryption of SSL-protected data when a cipher suite uses a block cipher in CBC mode. 19) An error in the USB component can be exploited to corrupt memory by attaching a malicious USB device. SOLUTION: Update to version 10.8.2 or 10.7.5 or apply Security Update 2012-004. PROVIDED AND/OR DISCOVERED BY: The vendor credits: 4) Jesse Ruderman, Mozilla Corporation 5) aazubel via ZDI 11) An anonymous person 12, 17) Will Dormann, CERT/CC 13) Harald Wagener, Google 15) Derick Cassidy, XEquals Corporation 19) Andy Davis, NGS Secure ORIGINAL ADVISORY: Apple: http://support.apple.com/kb/HT5501 OTHER REFERENCES: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ DEEP LINKS: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ EXTENDED DESCRIPTION: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ EXTENDED SOLUTION: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ EXPLOIT: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ ---------------------------------------------------------------------- About: This Advisory was delivered by Secunia as a free service to help private users keeping their systems up to date against the latest vulnerabilities. Subscribe: http://secunia.com/advisories/secunia_security_advisories/ Definitions: (Criticality, Where etc.) http://secunia.com/advisories/about_secunia_advisories/ Please Note: Secunia recommends that you verify all advisories you receive by clicking the link. Secunia NEVER sends attached files with advisories. Secunia does not advise people to install third party patches, only use those supplied by the vendor. ---------------------------------------------------------------------- Unsubscribe: Secunia Security Advisories http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org ----------------------------------------------------------------------
VAR-201209-0361 CVE-2012-3722 plural Apple Used in products CoreMedia Service disruption in ( Application crash ) Vulnerabilities CVSS V2: 6.8
CVSS V3: -
Severity: MEDIUM
The Sorenson codec in QuickTime in Apple Mac OS X before 10.7.5, and in CoreMedia in iOS before 6, accesses uninitialized memory locations, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with Sorenson encoding. Apple iOS for the iPhone, the iPod touch, and the iPad is prone to a remote code-execution vulnerability that affects the 'CoreMedia' component. Successfully exploiting this issue will allow attackers to execute arbitrary code in the context of the application or cause denial-of-service conditions. Note: This issue was previously discussed in BID 55612 (Apple iPhone/iPad/iPod touch Prior to iOS 6 Multiple Vulnerabilities) but has been given its own record to better document it. Apple Mac OS X is a dedicated operating system developed by Apple for Mac computers. ---------------------------------------------------------------------- The final version of the CSI 6.0 has been released. Find out why this is not just another Patch Management solution: http://secunia.com/blog/325/ ---------------------------------------------------------------------- TITLE: Apple Mac OS X Multiple Vulnerabilities SECUNIA ADVISORY ID: SA50628 VERIFY ADVISORY: Secunia.com http://secunia.com/advisories/50628/ Customer Area (Credentials Required) https://ca.secunia.com/?page=viewadvisory&vuln_id=50628 RELEASE DATE: 2012-09-20 DISCUSS ADVISORY: http://secunia.com/advisories/50628/#comments AVAILABLE ON SITE AND IN CUSTOMER AREA: * Last Update * Popularity * Comments * Criticality Level * Impact * Where * Solution Status * Operating System / Software * CVE Reference(s) http://secunia.com/advisories/50628/ ONLY AVAILABLE IN CUSTOMER AREA: * Authentication Level * Report Reliability * Secunia PoC * Secunia Analysis * Systems Affected * Approve Distribution * Remediation Status * Secunia CVSS Score * CVSS https://ca.secunia.com/?page=viewadvisory&vuln_id=50628 ONLY AVAILABLE WITH SECUNIA CSI AND SECUNIA PSI: * AUTOMATED SCANNING http://secunia.com/vulnerability_scanning/personal/ http://secunia.com/vulnerability_scanning/corporate/wsus_sccm_3rd_third_party_patching/ DESCRIPTION: Apple has issued a security update for Mac OS X, which fixes multiple vulnerabilities. 1) Various vulnerabilities exist in the bundled version of Apache. For more information: SA46288 SA45793 SA46987 SA47779 SA47410 2) An assertion error in BIND when handling DNS records can be exploited to cause a DoS (Denial of Service). For more information: SA46887 3) An error in BIND can be exploited to disclose potentially sensitive information or cause a DoS. For more information: SA49338 4) An error in the CoreText component when handling text glyphs can be exploited to cause a buffer overflow and potentially compromise an application using the component. 5) An error in the DirectoryService Proxy can be exploited to cause a buffer overflow. 6) Errors in the ImageIO component when parsing PNG images can be exploited to corrupt memory. For more information: SA48026 SA48587 7) An integer overflow error in the ImageIO component when parsing TIFF images can be exploited to cause a buffer overflow. For more information: SA48684#1 8) A previous fix did not properly address an error in the Installer component that allowed users to obtain account information. The original fix ensured that passwords were not recorded to the system log, but did not remove the old system log entries containing passwords. This is related to: SA49039#1 9) An error in International Components for Unicode (ICU) when handling ICU locale IDs can be exploited to cause a stack-based buffer overflow. For more information: SA47146 10) A logic error in the kernel when handling debug system calls can be exploited by a malicious program to bypass sandbox restrictions. For more information: SA48288#3 11) An error in the LoginWindow component can be exploited by local users to obtain other users' login passwords. 12) An input validation error in Mail can be exploited to execute web plugins when viewing an e-mail message. 13) An error in Mobile Accounts can be exploited by a user with access to the contents of a mobile account to obtain the account password. 14) Multiple errors exist in the bundled version of PHP. For more information: SA49014 SA44335 15) An authentication error in Profile Manager Device Management private interface can be exploited to enumerate managed devices. 16) Various errors exist in the bundled versions of QuickLook and QuickTime. For more information: SA47447 17) An uninitialised memory access error exists in QuickTime when viewing Sorenson-encoded movie files. 18) An error in Ruby may allow decryption of SSL-protected data when a cipher suite uses a block cipher in CBC mode. 19) An error in the USB component can be exploited to corrupt memory by attaching a malicious USB device. SOLUTION: Update to version 10.8.2 or 10.7.5 or apply Security Update 2012-004. PROVIDED AND/OR DISCOVERED BY: The vendor credits: 4) Jesse Ruderman, Mozilla Corporation 5) aazubel via ZDI 11) An anonymous person 12, 17) Will Dormann, CERT/CC 13) Harald Wagener, Google 15) Derick Cassidy, XEquals Corporation 19) Andy Davis, NGS Secure ORIGINAL ADVISORY: Apple: http://support.apple.com/kb/HT5501 OTHER REFERENCES: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ DEEP LINKS: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ EXTENDED DESCRIPTION: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ EXTENDED SOLUTION: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ EXPLOIT: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ ---------------------------------------------------------------------- About: This Advisory was delivered by Secunia as a free service to help private users keeping their systems up to date against the latest vulnerabilities. Subscribe: http://secunia.com/advisories/secunia_security_advisories/ Definitions: (Criticality, Where etc.) http://secunia.com/advisories/about_secunia_advisories/ Please Note: Secunia recommends that you verify all advisories you receive by clicking the link. Secunia NEVER sends attached files with advisories. Secunia does not advise people to install third party patches, only use those supplied by the vendor. ---------------------------------------------------------------------- Unsubscribe: Secunia Security Advisories http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org ---------------------------------------------------------------------- . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 APPLE-SA-2012-09-24-1 Apple TV 5.1 Apple TV 5.1 is now available and addresses the following: Apple TV Available for: Apple TV 2nd generation and later Impact: Viewing a maliciously crafted movie file may lead to an unexpected application termination or arbitrary code execution Description: An uninitialized memory access existed in the handling of Sorenson encoded movie files. This issue was addressed through improved memory initialization. CVE-ID CVE-2012-3722 : Will Dormann of the CERT/CC Apple TV Available for: Apple TV 2nd generation and later Impact: A malicious Wi-Fi network may be able to determine networks a device has previously accessed Description: Upon connecting to a Wi-Fi network, iOS may broadcast MAC addresses of previously accessed networks per the DNAv4 protocol. This issue was addressed by disabling DNAv4 on unencrypted Wi-Fi networks CVE-ID CVE-2012-3725 : Mark Wuergler of Immunity, Inc. Apple TV Available for: Apple TV 2nd generation and later Impact: Viewing a maliciously crafted TIFF file may lead to an unexpected application termination or arbitrary code execution Description: A buffer overflow existed in libtiff's handling of ThunderScan encoded TIFF images. This issue was addressed by updating libtiff to version 3.9.5. CVE-ID CVE-2011-1167 Apple TV Available for: Apple TV 2nd generation and later Impact: Viewing a maliciously crafted PNG image may lead to an unexpected application termination or arbitrary code execution Description: Multiple memory corruption issues existed in libpng's handling of PNG images. These issues were addressed through improved validation of PNG images. CVE-ID CVE-2011-3026 : Juri Aedla CVE-2011-3048 CVE-2011-3328 Apple TV Available for: Apple TV 2nd generation and later Impact: Viewing a maliciously crafted JPEG image may lead to an unexpected application termination or arbitrary code execution Description: A double free issue existed in ImageIO's handling of JPEG images. This issue was addressed through improved memory management. CVE-ID CVE-2012-3726 : Phil of PKJE Consulting Apple TV Available for: Apple TV 2nd generation and later Impact: Viewing a maliciously crafted TIFF image may lead to an unexpected application termination or arbitrary code execution Description: An integer overflow issue existed in libTIFF's handling of TIFF images. This issue was addressed through improved validation of TIFF images. This issue does not affect OS X Mountain Lion systems. CVE-ID CVE-2012-1173 Apple TV Available for: Apple TV 2nd generation and later Impact: Applications that use ICU may be vulnerable to an unexpected application termination or arbitrary code execution Description: A stack buffer overflow existed in the handling of ICU locale IDs. This issue was addressed through improved bounds checking. These issues were addressed by applying the relevant upstream patches. CVE-ID CVE-2011-1944 : Chris Evans of Google Chrome Security Team CVE-2011-2821 : Yang Dingning of NCNIPC, Graduate University of Chinese Academy of Sciences CVE-2011-2834 : Yang Dingning of NCNIPC, Graduate University of Chinese Academy of Sciences CVE-2011-3919 : Juri Aedla Apple TV Available for: Apple TV 2nd generation and later Impact: An attacker with a privileged network position may cause an unexpected application termination or arbitrary code execution Description: Multiple memory corruption issues existed in JavaScriptCore. These issues were addressed through improved memory handling. CVE-ID CVE-2012-0682 : Apple Product Security CVE-2012-0683 : Dave Mandelin of Mozilla CVE-2012-3589 : Dave Mandelin of Mozilla CVE-2012-3590 : Apple Product Security CVE-2012-3591 : Apple Product Security CVE-2012-3592 : Apple Product Security CVE-2012-3678 : Apple Product Security CVE-2012-3679 : Chris Leary of Mozilla Installation note: Apple TV will periodically check for software updates. Alternatively, you may manually check for software updates by selecting "Settings -> General -> Update Software". To check the current version of software, select "Settings -> General -> About". Information will also be posted to the Apple Security Updates web site: http://support.apple.com/kb/HT1222 This message is signed with Apple's Product Security PGP key, and details are available at: https://www.apple.com/support/security/pgp/ -----BEGIN PGP SIGNATURE----- Version: GnuPG/MacGPG2 v2.0.17 (Darwin) Comment: GPGTools - http://gpgtools.org iQIcBAEBAgAGBQJQXO50AAoJEPefwLHPlZEwc40P/AmBKys+PAsdT8gGrSpOY1B9 8h+Y0xdE+Hmesq9D4p6wvdY/lR+zMqtSwT6amNImYCIaRmm1P8+r8n31be52TYlg 7GqEAZbDtFztHwIISC8Khf8dMvWSrLhzRa7X/cxlIgRKmoXFnqJZzYcUov/M9Uw8 KwejQnztmAx7srHnZCNI+dxFqAC7hPoegnDnlVPx1DkwKDjt8q9xD3PGQyiGWWkI wqUEWvMGWr65CFyA7R0hDqKuNCowWn2cKP1UhIoEur5yRmc4aQVtOnHhJ8k9mdoO +58JC/y8lCtqGUyEL2Ar0FmIcRX/GJf+/isKOtmHx0JuEhH5beQ6s9FxU5eNR9DH EVPmVXowY9wMvKxwHFU3jwq8kQ3+IYC+7KA6lScb5mXO5mC5dbJPLp7uJto7+VtI atgQmvzdB8G562wpwTPuA4UQWWr0i6WWl8zkfgkRHO+cXyN683rkBP/vVEo9FipR YkQ10RsXqYDRXBcRywmTZZwQy6txMtV9D2bnk1uukQHBsZh30/mEpcmZbo6CO3s3 mnOtu5D2OQsNt4MqbviUkEgdc9JIJnqAOo+9YguDCEu6Rd7unbKB3RpmD+A3OJnR GhEa2Gqyvm/ozfb2D4L01y4UQo7dMLw+t/FOZXkrpdLlWn2LANWvXDCPSzIFCKoN cXF+ij425pfY+d7Iekz3 =PSL+ -----END PGP SIGNATURE-----
VAR-201209-0355 CVE-2012-3715 Apple Safari 6.0.1 Vulnerability that can obtain important information in less than CVSS V2: 4.3
CVSS V3: -
Severity: MEDIUM
Apple Safari before 6.0.1 makes http requests for https URIs in certain circumstances involving a paste into the address bar, which allows user-assisted remote attackers to obtain sensitive information by sniffing the network. Apple Safari is prone to a security-bypass vulnerability. Attackers can exploit this issue to bypass certain security restrictions and gain access to potentially sensitive information. Apple Safari versions prior to 6.0.1 are vulnerable. Apple Apple Safari is a web browser developed by Apple (Apple), and is the default browser included with Mac OS X and iOS operating systems. ---------------------------------------------------------------------- The final version of the CSI 6.0 has been released. Find out why this is not just another Patch Management solution: http://secunia.com/blog/325/ ---------------------------------------------------------------------- TITLE: Apple Safari for Mac OS X Multiple Vulnerabilities SECUNIA ADVISORY ID: SA50577 VERIFY ADVISORY: Secunia.com http://secunia.com/advisories/50577/ Customer Area (Credentials Required) https://ca.secunia.com/?page=viewadvisory&vuln_id=50577 RELEASE DATE: 2012-09-20 DISCUSS ADVISORY: http://secunia.com/advisories/50577/#comments AVAILABLE ON SITE AND IN CUSTOMER AREA: * Last Update * Popularity * Comments * Criticality Level * Impact * Where * Solution Status * Operating System / Software * CVE Reference(s) http://secunia.com/advisories/50577/ ONLY AVAILABLE IN CUSTOMER AREA: * Authentication Level * Report Reliability * Secunia PoC * Secunia Analysis * Systems Affected * Approve Distribution * Remediation Status * Secunia CVSS Score * CVSS https://ca.secunia.com/?page=viewadvisory&vuln_id=50577 ONLY AVAILABLE WITH SECUNIA CSI AND SECUNIA PSI: * AUTOMATED SCANNING http://secunia.com/vulnerability_scanning/personal/ http://secunia.com/vulnerability_scanning/corporate/wsus_sccm_3rd_third_party_patching/ DESCRIPTION: Multiple vulnerabilities have been reported in Safari, which can be exploited by malicious people to bypass certain security restrictions, gain knowledge of sensitive information, or compromise a user's system. 1) A logic error in the handling of the Quarantine attribute when opening HTML documents in safe mode can be exploited to cause the document to not be opened in safe mode and disclose the contents of arbitrary files. 2) An error in the handling of Form Autofill may lead to Address Book "Me" card details being disclosed when using Form Autofill on a specially crafted web page. 3) A logic error when handling HTTPS URLs in the address bar may cause a request to be unexpectedly sent over HTTP if part of the request in the address bar was edited by pasting text. 4) A use-after-free error in the Webkit Cascading Style Sheets (CSS) implementation when handling the :first-letter pseudo-element can be exploited to dereference already freed memory. 5) A use-after-free error in Webkit when handling tables with sections can be exploited to dereference already freed memory. 6) A use-after-free error in Webkit when handling the layout of documents using the Cascading Style Sheets (CSS) counters feature can be exploited to dereference already freed memory. 7) A use-after-free error in the Webkit Cascading Style Sheets (CSS) implementation when handling the :first-letter pseudo-element can be exploited to dereference already freed memory. 8) A use-after-free error in Webkit when handling SVG references can be exploited to dereference already freed memory. 9) A use-after-free error in Webkit when handling counters can be exploited to dereference already freed memory. 10) A use-after-free error in Webkit when handling layout height tracking can be exploited to dereference already freed memory. 11) An unspecified error in Webkit can be exploited to corrupt memory. 12) An unspecified error in Webkit can be exploited to corrupt memory. 13) An unspecified error in Webkit can be exploited to corrupt memory. 14) An unspecified error in Webkit can be exploited to corrupt memory. 15) An unspecified error in Webkit can be exploited to corrupt memory. 16) An unspecified error in Webkit can be exploited to corrupt memory. 17) An unspecified error in Webkit can be exploited to corrupt memory. 18) An unspecified error in Webkit can be exploited to corrupt memory. 19) An unspecified error in Webkit can be exploited to corrupt memory. 20) An unspecified error in Webkit can be exploited to corrupt memory. 21) An unspecified error in Webkit can be exploited to corrupt memory. 22) An unspecified error in Webkit can be exploited to corrupt memory. 23) An unspecified error in Webkit can be exploited to corrupt memory. 24) An unspecified error in Webkit can be exploited to corrupt memory. 25) An unspecified error in Webkit can be exploited to corrupt memory. 26) An unspecified error in Webkit can be exploited to corrupt memory. 27) An unspecified error in Webkit can be exploited to corrupt memory. 28) An unspecified error in Webkit can be exploited to corrupt memory. 29) An unspecified error in Webkit can be exploited to corrupt memory. 30) An unspecified error in Webkit can be exploited to corrupt memory. 31) An unspecified error in Webkit can be exploited to corrupt memory. 32) An unspecified error in Webkit can be exploited to corrupt memory. 33) An unspecified error in Webkit can be exploited to corrupt memory. 34) An unspecified error in Webkit can be exploited to corrupt memory. 35) An unspecified error in Webkit can be exploited to corrupt memory. 36) An unspecified error in Webkit can be exploited to corrupt memory. 37) An unspecified error in Webkit can be exploited to corrupt memory. 38) An unspecified error in Webkit can be exploited to corrupt memory. 39) An unspecified error in Webkit can be exploited to corrupt memory. 40) An unspecified error in Webkit can be exploited to corrupt memory. 41) An unspecified error in Webkit can be exploited to corrupt memory. 42) An unspecified error in Webkit can be exploited to corrupt memory. 43) An unspecified error in Webkit can be exploited to corrupt memory. 44) An unspecified error in Webkit can be exploited to corrupt memory. 45) An unspecified error in Webkit can be exploited to corrupt memory. 46) An unspecified error in Webkit can be exploited to corrupt memory. 47) An unspecified error in Webkit can be exploited to corrupt memory. 48) An unspecified error in Webkit can be exploited to corrupt memory. 49) An unspecified error in Webkit can be exploited to corrupt memory. 50) An unspecified error in Webkit can be exploited to corrupt memory. 51) An unspecified error in Webkit can be exploited to corrupt memory. 52) An unspecified error in Webkit can be exploited to corrupt memory. 53) An unspecified error in Webkit can be exploited to corrupt memory. 54) An unspecified error in Webkit can be exploited to corrupt memory. 55) An unspecified error in Webkit can be exploited to corrupt memory. 56) An unspecified error in Webkit can be exploited to corrupt memory. 57) An unspecified error in Webkit can be exploited to corrupt memory. 58) An unspecified error in Webkit can be exploited to corrupt memory. 59) An unspecified error in Webkit can be exploited to corrupt memory. 60) An unspecified error in Webkit can be exploited to corrupt memory. 61) An unspecified error in Webkit can be exploited to corrupt memory. SOLUTION: Update to version 6.0.1. PROVIDED AND/OR DISCOVERED BY: The vendor credits: 1) Aaron Sigel, vtty.com and Masahiro Yamada 2) Jonathan Hogervorst, Buzzera 3) Aaron Rhoads, East Watch Services LLC and Pepi Zawodsky 4-10, 13) miaubiz 11, 20, 34, 42, 44, 47, 49, 52, 55, 57, 58) Apple Product Security 12) Martin Barbella, Google Chrome Security Team 14, 15, 17, 19, 22, 25, 28, 33, 36, 38-40, 46, 48, 50, 51, 54, 56, 61) Abhishek Arya (Inferno), Google Chrome Security Team 16, 21, 23, 24, 26, 27, 32, 47, 53, 60) Skylined, Google Chrome Security Team 18) Yong Li, Research In Motion 29) Dominic Cooney, Google and Martin Barbella, Google Chrome Security Team 30) Abhishek Arya and Martin Barbella, Google Chrome Security Team 31) Martin Barbella, Google Chrome Security Team 35) Mario Gomes, netfuzzer.blogspot.com and Abhishek Arya (Inferno), Google Chrome Security Team 37) Skylined and Martin Barbella, Google Chrome Security Team 41) Julien Chaffraix, Chromium development community 43, 45) kuzzcc 59) James Robinson of Google ORIGINAL ADVISORY: Apple: http://support.apple.com/kb/HT5502 OTHER REFERENCES: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ DEEP LINKS: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ EXTENDED DESCRIPTION: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ EXTENDED SOLUTION: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ EXPLOIT: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ ---------------------------------------------------------------------- About: This Advisory was delivered by Secunia as a free service to help private users keeping their systems up to date against the latest vulnerabilities. Subscribe: http://secunia.com/advisories/secunia_security_advisories/ Definitions: (Criticality, Where etc.) http://secunia.com/advisories/about_secunia_advisories/ Please Note: Secunia recommends that you verify all advisories you receive by clicking the link. Secunia NEVER sends attached files with advisories. Secunia does not advise people to install third party patches, only use those supplied by the vendor. ---------------------------------------------------------------------- Unsubscribe: Secunia Security Advisories http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org ----------------------------------------------------------------------
VAR-201209-0354 CVE-2012-3714 Apple Safari 6.0.1 Less than Form Autofill In function Me Vulnerability to obtain card information CVSS V2: 4.3
CVSS V3: -
Severity: MEDIUM
The Form Autofill feature in Apple Safari before 6.0.1 does not restrict the filled fields to the set of fields contained in an Autofill popover, which allows remote attackers to obtain the Me card from an Address Book via a crafted web site. Apple Safari is prone to an information-disclosure vulnerability. An attacker can exploit this issue to obtain sensitive information that may lead to further attacks. Apple Safari versions prior to 6.0.1 are vulnerable. Apple Apple Safari is a web browser developed by Apple (Apple), and is the default browser included with Mac OS X and iOS operating systems. ---------------------------------------------------------------------- The final version of the CSI 6.0 has been released. Find out why this is not just another Patch Management solution: http://secunia.com/blog/325/ ---------------------------------------------------------------------- TITLE: Apple Safari for Mac OS X Multiple Vulnerabilities SECUNIA ADVISORY ID: SA50577 VERIFY ADVISORY: Secunia.com http://secunia.com/advisories/50577/ Customer Area (Credentials Required) https://ca.secunia.com/?page=viewadvisory&vuln_id=50577 RELEASE DATE: 2012-09-20 DISCUSS ADVISORY: http://secunia.com/advisories/50577/#comments AVAILABLE ON SITE AND IN CUSTOMER AREA: * Last Update * Popularity * Comments * Criticality Level * Impact * Where * Solution Status * Operating System / Software * CVE Reference(s) http://secunia.com/advisories/50577/ ONLY AVAILABLE IN CUSTOMER AREA: * Authentication Level * Report Reliability * Secunia PoC * Secunia Analysis * Systems Affected * Approve Distribution * Remediation Status * Secunia CVSS Score * CVSS https://ca.secunia.com/?page=viewadvisory&vuln_id=50577 ONLY AVAILABLE WITH SECUNIA CSI AND SECUNIA PSI: * AUTOMATED SCANNING http://secunia.com/vulnerability_scanning/personal/ http://secunia.com/vulnerability_scanning/corporate/wsus_sccm_3rd_third_party_patching/ DESCRIPTION: Multiple vulnerabilities have been reported in Safari, which can be exploited by malicious people to bypass certain security restrictions, gain knowledge of sensitive information, or compromise a user's system. 1) A logic error in the handling of the Quarantine attribute when opening HTML documents in safe mode can be exploited to cause the document to not be opened in safe mode and disclose the contents of arbitrary files. 3) A logic error when handling HTTPS URLs in the address bar may cause a request to be unexpectedly sent over HTTP if part of the request in the address bar was edited by pasting text. 4) A use-after-free error in the Webkit Cascading Style Sheets (CSS) implementation when handling the :first-letter pseudo-element can be exploited to dereference already freed memory. 5) A use-after-free error in Webkit when handling tables with sections can be exploited to dereference already freed memory. 6) A use-after-free error in Webkit when handling the layout of documents using the Cascading Style Sheets (CSS) counters feature can be exploited to dereference already freed memory. 7) A use-after-free error in the Webkit Cascading Style Sheets (CSS) implementation when handling the :first-letter pseudo-element can be exploited to dereference already freed memory. 8) A use-after-free error in Webkit when handling SVG references can be exploited to dereference already freed memory. 9) A use-after-free error in Webkit when handling counters can be exploited to dereference already freed memory. 10) A use-after-free error in Webkit when handling layout height tracking can be exploited to dereference already freed memory. 11) An unspecified error in Webkit can be exploited to corrupt memory. 12) An unspecified error in Webkit can be exploited to corrupt memory. 13) An unspecified error in Webkit can be exploited to corrupt memory. 14) An unspecified error in Webkit can be exploited to corrupt memory. 15) An unspecified error in Webkit can be exploited to corrupt memory. 16) An unspecified error in Webkit can be exploited to corrupt memory. 17) An unspecified error in Webkit can be exploited to corrupt memory. 18) An unspecified error in Webkit can be exploited to corrupt memory. 19) An unspecified error in Webkit can be exploited to corrupt memory. 20) An unspecified error in Webkit can be exploited to corrupt memory. 21) An unspecified error in Webkit can be exploited to corrupt memory. 22) An unspecified error in Webkit can be exploited to corrupt memory. 23) An unspecified error in Webkit can be exploited to corrupt memory. 24) An unspecified error in Webkit can be exploited to corrupt memory. 25) An unspecified error in Webkit can be exploited to corrupt memory. 26) An unspecified error in Webkit can be exploited to corrupt memory. 27) An unspecified error in Webkit can be exploited to corrupt memory. 28) An unspecified error in Webkit can be exploited to corrupt memory. 29) An unspecified error in Webkit can be exploited to corrupt memory. 30) An unspecified error in Webkit can be exploited to corrupt memory. 31) An unspecified error in Webkit can be exploited to corrupt memory. 32) An unspecified error in Webkit can be exploited to corrupt memory. 33) An unspecified error in Webkit can be exploited to corrupt memory. 34) An unspecified error in Webkit can be exploited to corrupt memory. 35) An unspecified error in Webkit can be exploited to corrupt memory. 36) An unspecified error in Webkit can be exploited to corrupt memory. 37) An unspecified error in Webkit can be exploited to corrupt memory. 38) An unspecified error in Webkit can be exploited to corrupt memory. 39) An unspecified error in Webkit can be exploited to corrupt memory. 40) An unspecified error in Webkit can be exploited to corrupt memory. 41) An unspecified error in Webkit can be exploited to corrupt memory. 42) An unspecified error in Webkit can be exploited to corrupt memory. 43) An unspecified error in Webkit can be exploited to corrupt memory. 44) An unspecified error in Webkit can be exploited to corrupt memory. 45) An unspecified error in Webkit can be exploited to corrupt memory. 46) An unspecified error in Webkit can be exploited to corrupt memory. 47) An unspecified error in Webkit can be exploited to corrupt memory. 48) An unspecified error in Webkit can be exploited to corrupt memory. 49) An unspecified error in Webkit can be exploited to corrupt memory. 50) An unspecified error in Webkit can be exploited to corrupt memory. 51) An unspecified error in Webkit can be exploited to corrupt memory. 52) An unspecified error in Webkit can be exploited to corrupt memory. 53) An unspecified error in Webkit can be exploited to corrupt memory. 54) An unspecified error in Webkit can be exploited to corrupt memory. 55) An unspecified error in Webkit can be exploited to corrupt memory. 56) An unspecified error in Webkit can be exploited to corrupt memory. 57) An unspecified error in Webkit can be exploited to corrupt memory. 58) An unspecified error in Webkit can be exploited to corrupt memory. 59) An unspecified error in Webkit can be exploited to corrupt memory. 60) An unspecified error in Webkit can be exploited to corrupt memory. 61) An unspecified error in Webkit can be exploited to corrupt memory. SOLUTION: Update to version 6.0.1. PROVIDED AND/OR DISCOVERED BY: The vendor credits: 1) Aaron Sigel, vtty.com and Masahiro Yamada 2) Jonathan Hogervorst, Buzzera 3) Aaron Rhoads, East Watch Services LLC and Pepi Zawodsky 4-10, 13) miaubiz 11, 20, 34, 42, 44, 47, 49, 52, 55, 57, 58) Apple Product Security 12) Martin Barbella, Google Chrome Security Team 14, 15, 17, 19, 22, 25, 28, 33, 36, 38-40, 46, 48, 50, 51, 54, 56, 61) Abhishek Arya (Inferno), Google Chrome Security Team 16, 21, 23, 24, 26, 27, 32, 47, 53, 60) Skylined, Google Chrome Security Team 18) Yong Li, Research In Motion 29) Dominic Cooney, Google and Martin Barbella, Google Chrome Security Team 30) Abhishek Arya and Martin Barbella, Google Chrome Security Team 31) Martin Barbella, Google Chrome Security Team 35) Mario Gomes, netfuzzer.blogspot.com and Abhishek Arya (Inferno), Google Chrome Security Team 37) Skylined and Martin Barbella, Google Chrome Security Team 41) Julien Chaffraix, Chromium development community 43, 45) kuzzcc 59) James Robinson of Google ORIGINAL ADVISORY: Apple: http://support.apple.com/kb/HT5502 OTHER REFERENCES: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ DEEP LINKS: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ EXTENDED DESCRIPTION: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ EXTENDED SOLUTION: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ EXPLOIT: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ ---------------------------------------------------------------------- About: This Advisory was delivered by Secunia as a free service to help private users keeping their systems up to date against the latest vulnerabilities. Subscribe: http://secunia.com/advisories/secunia_security_advisories/ Definitions: (Criticality, Where etc.) http://secunia.com/advisories/about_secunia_advisories/ Please Note: Secunia recommends that you verify all advisories you receive by clicking the link. Secunia NEVER sends attached files with advisories. Secunia does not advise people to install third party patches, only use those supplied by the vendor. ---------------------------------------------------------------------- Unsubscribe: Secunia Security Advisories http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org ----------------------------------------------------------------------
VAR-201209-0353 CVE-2012-3713 Safari vulnerable to local file content disclosure CVSS V2: 4.3
CVSS V3: -
Severity: MEDIUM
Apple Safari before 6.0.1 does not properly handle the Quarantine attribute of HTML documents, which allows user-assisted remote attackers to read arbitrary files by leveraging the presence of a downloaded document. Safari contains a vulnerability where a local file may be accessed from remote, which may result in a local file content disclosure. Masahiro YAMADA reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.By opening a specially crafted HTML document as a local file, an arbitrary local file may be obtained from remote even though access from other users is restricted. Apple Safari is prone to an information-disclosure vulnerability. An attacker can exploit this issue to obtain sensitive information that may lead to further attacks. Apple Safari versions prior to 6.0.1 are vulnerable. Apple Apple Safari is a web browser developed by Apple (Apple), and is the default browser included with Mac OS X and iOS operating systems. ---------------------------------------------------------------------- The final version of the CSI 6.0 has been released. Find out why this is not just another Patch Management solution: http://secunia.com/blog/325/ ---------------------------------------------------------------------- TITLE: Apple Safari for Mac OS X Multiple Vulnerabilities SECUNIA ADVISORY ID: SA50577 VERIFY ADVISORY: Secunia.com http://secunia.com/advisories/50577/ Customer Area (Credentials Required) https://ca.secunia.com/?page=viewadvisory&vuln_id=50577 RELEASE DATE: 2012-09-20 DISCUSS ADVISORY: http://secunia.com/advisories/50577/#comments AVAILABLE ON SITE AND IN CUSTOMER AREA: * Last Update * Popularity * Comments * Criticality Level * Impact * Where * Solution Status * Operating System / Software * CVE Reference(s) http://secunia.com/advisories/50577/ ONLY AVAILABLE IN CUSTOMER AREA: * Authentication Level * Report Reliability * Secunia PoC * Secunia Analysis * Systems Affected * Approve Distribution * Remediation Status * Secunia CVSS Score * CVSS https://ca.secunia.com/?page=viewadvisory&vuln_id=50577 ONLY AVAILABLE WITH SECUNIA CSI AND SECUNIA PSI: * AUTOMATED SCANNING http://secunia.com/vulnerability_scanning/personal/ http://secunia.com/vulnerability_scanning/corporate/wsus_sccm_3rd_third_party_patching/ DESCRIPTION: Multiple vulnerabilities have been reported in Safari, which can be exploited by malicious people to bypass certain security restrictions, gain knowledge of sensitive information, or compromise a user's system. 2) An error in the handling of Form Autofill may lead to Address Book "Me" card details being disclosed when using Form Autofill on a specially crafted web page. 3) A logic error when handling HTTPS URLs in the address bar may cause a request to be unexpectedly sent over HTTP if part of the request in the address bar was edited by pasting text. 4) A use-after-free error in the Webkit Cascading Style Sheets (CSS) implementation when handling the :first-letter pseudo-element can be exploited to dereference already freed memory. 5) A use-after-free error in Webkit when handling tables with sections can be exploited to dereference already freed memory. 6) A use-after-free error in Webkit when handling the layout of documents using the Cascading Style Sheets (CSS) counters feature can be exploited to dereference already freed memory. 7) A use-after-free error in the Webkit Cascading Style Sheets (CSS) implementation when handling the :first-letter pseudo-element can be exploited to dereference already freed memory. 8) A use-after-free error in Webkit when handling SVG references can be exploited to dereference already freed memory. 9) A use-after-free error in Webkit when handling counters can be exploited to dereference already freed memory. 10) A use-after-free error in Webkit when handling layout height tracking can be exploited to dereference already freed memory. 11) An unspecified error in Webkit can be exploited to corrupt memory. 12) An unspecified error in Webkit can be exploited to corrupt memory. 13) An unspecified error in Webkit can be exploited to corrupt memory. 14) An unspecified error in Webkit can be exploited to corrupt memory. 15) An unspecified error in Webkit can be exploited to corrupt memory. 16) An unspecified error in Webkit can be exploited to corrupt memory. 17) An unspecified error in Webkit can be exploited to corrupt memory. 18) An unspecified error in Webkit can be exploited to corrupt memory. 19) An unspecified error in Webkit can be exploited to corrupt memory. 20) An unspecified error in Webkit can be exploited to corrupt memory. 21) An unspecified error in Webkit can be exploited to corrupt memory. 22) An unspecified error in Webkit can be exploited to corrupt memory. 23) An unspecified error in Webkit can be exploited to corrupt memory. 24) An unspecified error in Webkit can be exploited to corrupt memory. 25) An unspecified error in Webkit can be exploited to corrupt memory. 26) An unspecified error in Webkit can be exploited to corrupt memory. 27) An unspecified error in Webkit can be exploited to corrupt memory. 28) An unspecified error in Webkit can be exploited to corrupt memory. 29) An unspecified error in Webkit can be exploited to corrupt memory. 30) An unspecified error in Webkit can be exploited to corrupt memory. 31) An unspecified error in Webkit can be exploited to corrupt memory. 32) An unspecified error in Webkit can be exploited to corrupt memory. 33) An unspecified error in Webkit can be exploited to corrupt memory. 34) An unspecified error in Webkit can be exploited to corrupt memory. 35) An unspecified error in Webkit can be exploited to corrupt memory. 36) An unspecified error in Webkit can be exploited to corrupt memory. 37) An unspecified error in Webkit can be exploited to corrupt memory. 38) An unspecified error in Webkit can be exploited to corrupt memory. 39) An unspecified error in Webkit can be exploited to corrupt memory. 40) An unspecified error in Webkit can be exploited to corrupt memory. 41) An unspecified error in Webkit can be exploited to corrupt memory. 42) An unspecified error in Webkit can be exploited to corrupt memory. 43) An unspecified error in Webkit can be exploited to corrupt memory. 44) An unspecified error in Webkit can be exploited to corrupt memory. 45) An unspecified error in Webkit can be exploited to corrupt memory. 46) An unspecified error in Webkit can be exploited to corrupt memory. 47) An unspecified error in Webkit can be exploited to corrupt memory. 48) An unspecified error in Webkit can be exploited to corrupt memory. 49) An unspecified error in Webkit can be exploited to corrupt memory. 50) An unspecified error in Webkit can be exploited to corrupt memory. 51) An unspecified error in Webkit can be exploited to corrupt memory. 52) An unspecified error in Webkit can be exploited to corrupt memory. 53) An unspecified error in Webkit can be exploited to corrupt memory. 54) An unspecified error in Webkit can be exploited to corrupt memory. 55) An unspecified error in Webkit can be exploited to corrupt memory. 56) An unspecified error in Webkit can be exploited to corrupt memory. 57) An unspecified error in Webkit can be exploited to corrupt memory. 58) An unspecified error in Webkit can be exploited to corrupt memory. 59) An unspecified error in Webkit can be exploited to corrupt memory. 60) An unspecified error in Webkit can be exploited to corrupt memory. 61) An unspecified error in Webkit can be exploited to corrupt memory. SOLUTION: Update to version 6.0.1. PROVIDED AND/OR DISCOVERED BY: The vendor credits: 1) Aaron Sigel, vtty.com and Masahiro Yamada 2) Jonathan Hogervorst, Buzzera 3) Aaron Rhoads, East Watch Services LLC and Pepi Zawodsky 4-10, 13) miaubiz 11, 20, 34, 42, 44, 47, 49, 52, 55, 57, 58) Apple Product Security 12) Martin Barbella, Google Chrome Security Team 14, 15, 17, 19, 22, 25, 28, 33, 36, 38-40, 46, 48, 50, 51, 54, 56, 61) Abhishek Arya (Inferno), Google Chrome Security Team 16, 21, 23, 24, 26, 27, 32, 47, 53, 60) Skylined, Google Chrome Security Team 18) Yong Li, Research In Motion 29) Dominic Cooney, Google and Martin Barbella, Google Chrome Security Team 30) Abhishek Arya and Martin Barbella, Google Chrome Security Team 31) Martin Barbella, Google Chrome Security Team 35) Mario Gomes, netfuzzer.blogspot.com and Abhishek Arya (Inferno), Google Chrome Security Team 37) Skylined and Martin Barbella, Google Chrome Security Team 41) Julien Chaffraix, Chromium development community 43, 45) kuzzcc 59) James Robinson of Google ORIGINAL ADVISORY: Apple: http://support.apple.com/kb/HT5502 OTHER REFERENCES: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ DEEP LINKS: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ EXTENDED DESCRIPTION: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ EXTENDED SOLUTION: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ EXPLOIT: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ ---------------------------------------------------------------------- About: This Advisory was delivered by Secunia as a free service to help private users keeping their systems up to date against the latest vulnerabilities. Subscribe: http://secunia.com/advisories/secunia_security_advisories/ Definitions: (Criticality, Where etc.) http://secunia.com/advisories/about_secunia_advisories/ Please Note: Secunia recommends that you verify all advisories you receive by clicking the link. Secunia NEVER sends attached files with advisories. Secunia does not advise people to install third party patches, only use those supplied by the vendor. ---------------------------------------------------------------------- Unsubscribe: Secunia Security Advisories http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org ----------------------------------------------------------------------