Mac OS X < 10.9 Multiple Vulnerabilities

high Nessus Network Monitor Plugin ID 8040

Synopsis

The remote host is missing a Mac OS X update that fixes multiple security issues.

Description

The remote host is running a version of Mac OS X that is older than 10.9 (dubbed OS X Maverick). The newer version contains numerous security-related fixes for the following components :

- Application Firewall
- App Sandbox
- Bluetooth
- CFNetwork
- CFNetwork SSL
- Console
- CoreGraphics
- curl
- dyld
- IOKitUser
- IOSerialFamily
- Kernel
- Kext Management
- LaunchServices
- Libc
- Mail Accounts
- Mail Header Display
- Mail Networking
- OpenLDAP
- perl
- Power Management
- python
- ruby
- Security
- Security
- Authorization
- Security
- Smart Card Services
- Screen Lock
- Screen Sharing Server
- syslog
- USB

Solution

Upgrade to OS X 10.9 or higher.

See Also

http://support.apple.com/kb/HT6011

http://lists.apple.com/archives/security-announce/2013/Oct/msg00004.html

http://lists.apple.com/archives/security-announce/2013/Oct/msg00006.html

Plugin Details

Severity: High

ID: 8040

Family: Web Clients

Published: 10/25/2013

Updated: 3/6/2019

Dependencies: 1735, 8314

Nessus ID: 70561

Risk Information

Risk Factor: High

CVSS v2.0

Base Score: 9.3

Temporal Score: 8.1

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

Temporal Vector: CVSS2#E:ND/RL:OF/RC:C

CVSS v3.0

Base Score: 8.1

Temporal Score: 7.7

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:X/RL:O/RC:C

Vulnerability Information

CPE: cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*

Patch Publication Date: 10/22/2013

Vulnerability Publication Date: 10/22/2013

Reference Information

CVE: CVE-2011-2391, CVE-2013-5167, CVE-2013-5141, CVE-2013-5174, CVE-2013-5186, CVE-2013-5172, CVE-2013-5145, CVE-2013-3954, CVE-2013-5138, CVE-2013-5190, CVE-2013-5180, CVE-2013-5170, CVE-2013-5191, CVE-2013-5229, CVE-2013-5168, CVE-2013-5179, CVE-2013-5177, CVE-2013-3950, CVE-2013-5135, CVE-2013-5176, CVE-2013-5183, CVE-2013-5139, CVE-2013-5142, CVE-2013-5165, CVE-2013-5166, CVE-2013-5173, CVE-2013-5178, CVE-2013-5182, CVE-2013-5184, CVE-2013-5187, CVE-2013-5188, CVE-2013-5189, CVE-2013-5192

BID: 52379, 60843, 49778, 59058, 51239, 51996, 52732, 58311, 57842, 62531, 60437, 60444, 62520, 62522, 62523, 62529, 62536, 63282, 63284, 63290, 63311, 63312, 63313, 63314, 63316, 63317, 63319, 63320, 63321, 63322, 63329, 63330, 63331, 63332, 63335, 63336, 63339

IAVB: 2012-B-0006