Mac OS X Multiple Vulnerabilities (Security Update 2007-005)

Critical Nessus Plugin ID 25297


The remote host is missing a Mac OS X update that fixes several security issues.


The remote host is running a version of Mac OS X 10.4 or 10.3 that does not have Security Update 2007-005 applied.

This update fixes security flaws in the following applications :

Alias Manager BIND CoreGraphics crontabs fetchmail file iChat mDNSResponder PPP ruby screen texinfo VPN


Install Security Update 2007-005 :

See Also

Plugin Details

Severity: Critical

ID: 25297

File Name: macosx_SecUpd2007-005.nasl

Version: $Revision: 1.17 $

Type: local

Agent: macosx

Published: 2007/05/25

Modified: 2016/11/28

Dependencies: 12634

Risk Information

Risk Factor: Critical


Base Score: 10

Temporal Score: 9

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Temporal Vector: CVSS2#E:POC/RL:ND/RC:C

Vulnerability Information

CPE: cpe:/o:apple:mac_os_x

Required KB Items: Host/MacOSX/packages

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 2007/05/29

Vulnerability Publication Date: 2005/09/14

Exploitable With

Core Impact

Metasploit (Mac OS X mDNSResponder UPnP Location Overflow)

Reference Information

CVE: CVE-2005-3011, CVE-2006-4095, CVE-2006-4096, CVE-2006-4573, CVE-2006-5467, CVE-2006-6303, CVE-2007-0493, CVE-2007-0494, CVE-2007-0740, CVE-2007-0750, CVE-2007-0751, CVE-2007-0752, CVE-2007-0753, CVE-2007-1536, CVE-2007-1558, CVE-2007-2386, CVE-2007-2390

BID: 24144, 24159

OSVDB: 19409, 28557, 28558, 29905, 31922, 31923, 34237, 34238, 34285, 34856, 35141, 35142, 35143, 35144, 35145, 35146, 35147

CWE: 134, 399