Mac OS X Security Update 2007-001

medium Nessus Plugin ID 24234

Synopsis

The remote host is missing a Mac OS X update which fixes a security issue.

Description

The remote host is running a version of Mac OS X 10.3 or 10.4 which does not have Security Update 2007-001 applied.

This update fixes a flaw in QuickTime which may allow a rogue website to execute arbitrary code on the remote host by exploiting an overflow in the RTSP URL handler.

Solution

Install Security Update 2007-001.

See Also

http://docs.info.apple.com/article.html?artnum=304989

http://www.nessus.org/u?c80700ff

http://www.apple.com/support/downloads/securityupdate2007001panther.html

Plugin Details

Severity: Medium

ID: 24234

File Name: macosx_SecUpd2007-001.nasl

Version: 1.25

Type: local

Agent: macosx

Published: 1/24/2007

Updated: 11/27/2023

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: High

Score: 8.8

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5.9

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2007-0015

Vulnerability Information

CPE: cpe:/o:apple:mac_os_x

Required KB Items: Host/MacOSX/packages

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 1/16/2007

Vulnerability Publication Date: 1/1/2007

Exploitable With

CANVAS (CANVAS)

Core Impact

Metasploit (Apple QuickTime 7.1.3 RTSP URI Buffer Overflow)

Reference Information

CVE: CVE-2007-0015

BID: 21829