Mac OS X Security Update 2007-001

Medium Nessus Plugin ID 24234


The remote host is missing a Mac OS X update which fixes a security issue.


The remote host is running a version of Mac OS X 10.3 or 10.4 which does not have Security Update 2007-001 applied.

This update fixes a flaw in QuickTime which may allow a rogue website to execute arbitrary code on the remote host by exploiting an overflow in the RTSP URL handler.


Install Security Update 2007-001.

See Also

Plugin Details

Severity: Medium

ID: 24234

File Name: macosx_SecUpd2007-001.nasl

Version: 1.19

Type: local

Agent: macosx

Published: 2007/01/24

Modified: 2017/05/30

Dependencies: 12634

Risk Information

Risk Factor: Medium


Base Score: 6.8

Temporal Score: 5.9

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

Temporal Vector: CVSS2#E:H/RL:OF/RC:C

Vulnerability Information

CPE: cpe:/o:apple:mac_os_x

Required KB Items: Host/MacOSX/packages

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 2007/01/16

Vulnerability Publication Date: 2007/01/01

Exploitable With


Core Impact

Metasploit (Apple QuickTime 7.1.3 RTSP URI Buffer Overflow)

Reference Information

CVE: CVE-2007-0015

BID: 21829

OSVDB: 31023