Mac OS X : OS X Server < 4.1.5 BIND DoS

high Nessus Plugin ID 85410

Synopsis

The remote host is missing a security update for OS X Server.

Description

The remote Mac OS X host has a version of OS X Server installed that is prior to 4.1.5. It is, therefore, affected by a denial of service vulnerability due to an assertion flaw that occurs when handling TKEY queries. A remote attacker can exploit this, via a specially crafted request, to cause a REQUIRE assertion failure and daemon exit, resulting in a denial of service condition.

Solution

Upgrade to OS X Server version 4.1.5 or later.

Note that OS X Server 4.1.5 is available only for OS X 10.10.5 or later.

See Also

https://support.apple.com/en-us/HT205032

Plugin Details

Severity: High

ID: 85410

File Name: macosx_server_4_1_5.nasl

Version: 1.7

Type: local

Agent: macosx

Published: 8/17/2015

Updated: 7/14/2018

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.0

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Information

CPE: cpe:/o:apple:mac_os_x_server

Required KB Items: Host/local_checks_enabled, Host/MacOSX/Version, MacOSX/Server/Version

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 8/11/2015

Vulnerability Publication Date: 7/28/2014

Exploitable With

Core Impact

Reference Information

CVE: CVE-2015-5477

BID: 76092

APPLE-SA: APPLE-SA-2015-08-13-4