Mac OS X 10.9.5 and 10.10.5 Multiple Vulnerabilities (Security Update 2016-004)

critical Nessus Plugin ID 92497

Synopsis

The remote host is missing a Mac OS X update that fixes multiple vulnerabilities.

Description

The remote host is running a version of Mac OS X that is 10.9.5 or 10.10.5 and is missing Security Update 2016-004. It is, therefore, affected by multiple vulnerabilities in the following components :

- apache_mod_php (affects 10.10.5 only)
- CoreGraphics
- ImageIO
- libxml2
- libxslt

Note that successful exploitation of the most serious issues can result in arbitrary code execution.

Solution

Install Security Update 2016-004 or later.

See Also

https://support.apple.com/en-us/HT206903

http://www.nessus.org/u?5da74f53

Plugin Details

Severity: Critical

ID: 92497

File Name: macosx_SecUpd2016-004.nasl

Version: 1.9

Type: local

Agent: macosx

Published: 7/21/2016

Updated: 7/14/2018

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:apple:mac_os_x

Required KB Items: Host/local_checks_enabled, Host/MacOSX/Version, Host/MacOSX/packages/boms

Exploit Ease: No known exploits are available

Patch Publication Date: 7/18/2016

Vulnerability Publication Date: 7/18/2016

Reference Information

CVE: CVE-2013-7456, CVE-2016-1684, CVE-2016-1836, CVE-2016-4447, CVE-2016-4448, CVE-2016-4449, CVE-2016-4483, CVE-2016-4607, CVE-2016-4608, CVE-2016-4609, CVE-2016-4610, CVE-2016-4612, CVE-2016-4614, CVE-2016-4615, CVE-2016-4616, CVE-2016-4619, CVE-2016-4629, CVE-2016-4630, CVE-2016-4637, CVE-2016-4650, CVE-2016-5093, CVE-2016-5094, CVE-2016-5096

BID: 90856, 90857, 90859, 90861, 90864, 90865, 90876, 90946, 91824, 91826, 91834, 92034

APPLE-SA: APPLE-SA-2016-05-16-4