Mac OS X Multiple Vulnerabilities (Security Update 2010-004)

High Nessus Plugin ID 47024

Synopsis

The remote host is missing a Mac OS X update that fixes a security issue.

Description

The remote host is running a version of Mac OS X 10.5 that does not have Security Update 2010-004 applied.

This security update contains fixes for the following components :

- CUPS
- DesktopServices
- Flash Player plug-in
- Folder Manager
- iChat
- ImageIO
- Kerberos
- Kernel
- libcurl
- Network Authorization
- Ruby
- SMB File Server
- SquirrelMail
- Wiki Server

Solution

Install Security Update 2010-004 or later.

See Also

http://support.apple.com/kb/HT4188

http://lists.apple.com/archives/security-announce/2010/Jun/msg00001.html

Plugin Details

Severity: High

ID: 47024

File Name: macosx_SecUpd2010-004.nasl

Version: 1.20

Type: local

Agent: macosx

Published: 2010/06/15

Updated: 2018/07/14

Dependencies: 12634

Risk Information

Risk Factor: High

CVSS v2.0

Base Score: 9.3

Temporal Score: 7.7

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

Temporal Vector: CVSS2#E:F/RL:OF/RC:C

CVSS v3.0

Base Score: 8.8

Temporal Score: 8.1

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:F/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:apple:mac_os_x

Required KB Items: Host/MacOSX/packages, Host/uname

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 2010/06/15

Vulnerability Publication Date: 2009/05/08

Exploitable With

Core Impact

Reference Information

CVE: CVE-2009-1578, CVE-2009-1579, CVE-2009-1580, CVE-2009-1581, CVE-2009-2964, CVE-2009-4212, CVE-2010-0186, CVE-2010-0187, CVE-2010-0302, CVE-2010-0540, CVE-2010-0541, CVE-2010-0543, CVE-2010-0545, CVE-2010-0546, CVE-2010-0734, CVE-2010-1374, CVE-2010-1375, CVE-2010-1381, CVE-2010-1382, CVE-2010-1411, CVE-2010-1748, CVE-2010-1816, CVE-2010-1821

BID: 34916, 36196, 37749, 38198, 38200, 38510, 40887, 40889, 40892, 40893, 40894, 40895, 40896, 40897, 40898

CWE: 79, 94, 189, 287, 352, 399