Mac OS X < 10.4.9 Multiple Vulnerabilities (Security Update 2007-003)

High Nessus Network Monitor Plugin ID 3947

Synopsis

The remote host is missing a Mac OS X update that fixes a security issue.

Description

The remote host is running a version of Mac OS X 10.4 that is older than version 10.4.9 or a version of Mac OS X 10.3 that does not have Security Update 2007-003 applied. This update contains several security fixes for the following programs :

- ColorSync
- CoreGraphics
- Crash Reporter
- CUPS
- Disk Images
- DS Plugins
- Flash Player
- GNU Tar
- HFS
- HID Family
- ImageIO
- Kernel
- MySQL server
- Networking
- OpenSSH
- Printing
- QuickDraw Manager
- servermgrd
- SMB File Server
- Software Update
- sudo
- WebLog

Solution

Upgrade to version 10.4.9 or higher.

See Also

http://docs.info.apple.com/article.html?artnum=305214

Plugin Details

Severity: High

ID: 3947

File Name: 3947.prm

Family: Web Clients

Published: 2007/03/13

Modified: 2016/02/05

Dependencies: 1735, 8314

Nessus ID: 24811

Risk Information

Risk Factor: High

CVSSv2

Base Score: 8.3

Temporal Score: 6.1

Vector: CVSS2#AV:A/AC:L/Au:N/C:C/I:C/A:C

Temporal Vector: CVSS2#E:U/RL:OF/RC:C

CVSSv3

Base Score: 8.7

Temporal Score: 7.5

Vector: CVSS3#AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS3#E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:apple:mac_os_x

Reference Information

CVE: CVE-2007-0719, CVE-2007-0467, CVE-2007-0720, CVE-2007-0721, CVE-2007-0722, CVE-2006-6061, CVE-2006-6062, CVE-2006-5679, CVE-2007-0229, CVE-2007-0267, CVE-2007-0299, CVE-2007-0723, CVE-2006-5330, CVE-2006-0300, CVE-2006-6097, CVE-2007-0318, CVE-2007-0724, CVE-2007-1071, CVE-2007-0733, CVE-2006-5836, CVE-2006-6129, CVE-2006-6173, CVE-2006-1516, CVE-2006-1517, CVE-2006-2753, CVE-2006-3081, CVE-2006-4031, CVE-2006-4226, CVE-2006-3469, CVE-2006-6130, CVE-2007-0236, CVE-2007-0726, CVE-2006-0225, CVE-2006-4924, CVE-2006-5051, CVE-2006-5052, CVE-2007-0728, CVE-2007-0588, CVE-2007-0730, CVE-2007-0731, CVE-2007-0463, CVE-2005-2959, CVE-2006-1518, CVE-2006-4227, CVE-2006-4829

BID: 23127, 22222, 20026, 15191, 16369, 16764, 17780, 18219, 18439, 19032, 19279, 19559, 20216, 20241, 20245, 20592, 20918, 20982, 21201, 21235, 21236, 21291, 21317, 21349, 21993, 22036, 22041, 22228, 22630, 22948