Mac OS X < 10.9 Multiple Vulnerabilities

High Nessus Network Monitor Plugin ID 8040

Synopsis

The remote host is missing a Mac OS X update that fixes multiple security issues.

Description

The remote host is running a version of Mac OS X that is older than 10.9 (dubbed OS X Maverick). The newer version contains numerous security-related fixes for the following components :

- Application Firewall
- App Sandbox
- Bluetooth
- CFNetwork
- CFNetwork SSL
- Console
- CoreGraphics
- curl
- dyld
- IOKitUser
- IOSerialFamily
- Kernel
- Kext Management
- LaunchServices
- Libc
- Mail Accounts
- Mail Header Display
- Mail Networking
- OpenLDAP
- perl
- Power Management
- python
- ruby
- Security
- Security
- Authorization
- Security
- Smart Card Services
- Screen Lock
- Screen Sharing Server
- syslog
- USB

Solution

Upgrade to OS X 10.9 or higher.

See Also

http://support.apple.com/kb/HT6011

http://lists.apple.com/archives/security-announce/2013/Oct/msg00004.html

http://lists.apple.com/archives/security-announce/2013/Oct/msg00006.html

Plugin Details

Severity: High

ID: 8040

Family: Web Clients

Published: 2013/10/25

Updated: 2019/03/06

Dependencies: 1735, 8314

Nessus ID: 70561

Risk Information

Risk Factor: High

CVSS v2.0

Base Score: 9.3

Temporal Score: 8.1

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

Temporal Vector: CVSS2#E:ND/RL:OF/RC:C

CVSS v3.0

Base Score: 8.1

Temporal Score: 7.7

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:X/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:apple:mac_os_x

Patch Publication Date: 2013/10/22

Vulnerability Publication Date: 2013/10/22

Reference Information

CVE: CVE-2011-2391, CVE-2013-3950, CVE-2013-3954, CVE-2013-5135, CVE-2013-5138, CVE-2013-5139, CVE-2013-5141, CVE-2013-5142, CVE-2013-5145, CVE-2013-5165, CVE-2013-5166, CVE-2013-5167, CVE-2013-5168, CVE-2013-5170, CVE-2013-5172, CVE-2013-5173, CVE-2013-5174, CVE-2013-5176, CVE-2013-5177, CVE-2013-5178, CVE-2013-5179, CVE-2013-5180, CVE-2013-5182, CVE-2013-5183, CVE-2013-5184, CVE-2013-5186, CVE-2013-5187, CVE-2013-5188, CVE-2013-5189, CVE-2013-5190, CVE-2013-5191, CVE-2013-5192, CVE-2013-5229

BID: 49778, 51239, 51996, 52379, 52732, 57842, 58311, 59058, 60437, 60444, 60843, 62520, 62522, 62523, 62529, 62531, 62536, 63282, 63284, 63290, 63311, 63312, 63313, 63314, 63316, 63317, 63319, 63320, 63321, 63322, 63329, 63330, 63331, 63332, 63335, 63336, 63339

IAVB: 2012-B-0006