Mac OS X 10.10.x < 10.10.5 多個弱點

high Nessus Plugin ID 85408
新推出!弱點優先順序評分 (VPR)

Tenable 會為每個弱點計算動態 VPR。VPR 將弱點資訊與威脅情報和機器學習演算法加以結合,藉此預測攻擊者最有可能利用哪些弱點發動攻擊。查看詳細資訊: VPR 是什麼?它跟 CVSS 有何不同?

VPR 評分: 8.9

Synopsis

遠端主機缺少可修正多個安全性弱點的 Mac OS X 更新。

描述

遠端主機執行的 Mac OS X 10.10.x 版本比 10.10.5 版舊。因此受到下列元件中的多個弱點影響:

- apache
- apache_mod_php
- Apple ID OD Plug-in
- AppleGraphicsControl
- Bluetooth
- bootp
- CloudKit
- CoreMedia Playback
- CoreText
- curl
- Data Detectors Engine
- Date & Time pref pane
- Dictionary Application
- DiskImages
- dyld
- FontParser
- groff
- ImageIO
- Install Framework Legacy
- IOFireWireFamily
- IOGraphics
- IOHIDFamily
- Kernel
- Libc
- Libinfo
- libpthread
- libxml2
- libxpc
- mail_cmds
- Notification Center OSX
- ntfs
- OpenSSH
- OpenSSL
- perl
- PostgreSQL
- python
- QL Office
- Quartz Composer Framework
- Quick Look
- QuickTime 7
- SceneKit
- Security
- SMBClient
- Speech UI
- sudo
- tcpdump
- Text Formats
- udf

請注意,如果成功惡意利用多數嚴重問題,將會導致任意程式碼執行。

解決方案

升級至 Mac OS X 10.10.5 或更新版本。

另請參閱

https://support.apple.com/en-us/HT205031

Plugin 詳細資訊

嚴重性: High

ID: 85408

檔案名稱: macosx_10_10_5.nasl

版本: 1.15

類型: combined

代理程式: macosx

已發布: 2015/8/17

已更新: 2018/7/16

相依性: ssh_get_info.nasl, os_fingerprint.nasl

風險資訊

風險因素: High

VPR 評分: 8.9

CVSS v2.0

基本分數: 9.3

時間分數: 8.1

媒介: AV:N/AC:M/Au:N/C:C/I:C/A:C

時間媒介: E:H/RL:OF/RC:C

弱點資訊

CPE: cpe:/o:apple:mac_os_x

可被惡意程式利用: true

可輕鬆利用: Exploits are available

修補程式發佈日期: 2015/8/11

弱點發布日期: 2009/7/24

惡意利用途徑

CANVAS (CANVAS)

Core Impact

Metasploit (Apple OS X DYLD_PRINT_TO_FILE Privilege Escalation)

參考資訊

CVE: CVE-2009-5044, CVE-2009-5078, CVE-2012-6685, CVE-2013-1775, CVE-2013-1776, CVE-2013-2776, CVE-2013-2777, CVE-2013-7040, CVE-2013-7338, CVE-2013-7422, CVE-2014-0067, CVE-2014-0106, CVE-2014-0191, CVE-2014-1912, CVE-2014-3581, CVE-2014-3583, CVE-2014-3613, CVE-2014-3620, CVE-2014-3660, CVE-2014-3707, CVE-2014-7185, CVE-2014-7844, CVE-2014-8109, CVE-2014-8150, CVE-2014-8151, CVE-2014-8161, CVE-2014-8767, CVE-2014-8769, CVE-2014-9140, CVE-2014-9365, CVE-2014-9680, CVE-2015-0228, CVE-2015-0241, CVE-2015-0242, CVE-2015-0243, CVE-2015-0244, CVE-2015-0253, CVE-2015-1788, CVE-2015-1789, CVE-2015-1790, CVE-2015-1791, CVE-2015-1792, CVE-2015-2783, CVE-2015-2787, CVE-2015-3143, CVE-2015-3144, CVE-2015-3145, CVE-2015-3148, CVE-2015-3153, CVE-2015-3183, CVE-2015-3185, CVE-2015-3307, CVE-2015-3329, CVE-2015-3330, CVE-2015-3729, CVE-2015-3730, CVE-2015-3731, CVE-2015-3732, CVE-2015-3733, CVE-2015-3734, CVE-2015-3735, CVE-2015-3736, CVE-2015-3737, CVE-2015-3738, CVE-2015-3739, CVE-2015-3740, CVE-2015-3741, CVE-2015-3742, CVE-2015-3743, CVE-2015-3744, CVE-2015-3745, CVE-2015-3746, CVE-2015-3747, CVE-2015-3748, CVE-2015-3749, CVE-2015-3750, CVE-2015-3751, CVE-2015-3752, CVE-2015-3753, CVE-2015-3754, CVE-2015-3755, CVE-2015-3757, CVE-2015-3760, CVE-2015-3761, CVE-2015-3762, CVE-2015-3764, CVE-2015-3765, CVE-2015-3766, CVE-2015-3767, CVE-2015-3768, CVE-2015-3769, CVE-2015-3770, CVE-2015-3771, CVE-2015-3772, CVE-2015-3773, CVE-2015-3774, CVE-2015-3775, CVE-2015-3776, CVE-2015-3777, CVE-2015-3778, CVE-2015-3779, CVE-2015-3780, CVE-2015-3781, CVE-2015-3782, CVE-2015-3783, CVE-2015-3784, CVE-2015-3786, CVE-2015-3787, CVE-2015-3788, CVE-2015-3789, CVE-2015-3790, CVE-2015-3791, CVE-2015-3792, CVE-2015-3794, CVE-2015-3795, CVE-2015-3796, CVE-2015-3797, CVE-2015-3798, CVE-2015-3799, CVE-2015-3800, CVE-2015-3802, CVE-2015-3803, CVE-2015-3804, CVE-2015-3805, CVE-2015-3806, CVE-2015-3807, CVE-2015-4021, CVE-2015-4022, CVE-2015-4024, CVE-2015-4025, CVE-2015-4026, CVE-2015-4147, CVE-2015-4148, CVE-2015-5600, CVE-2015-5747, CVE-2015-5748, CVE-2015-5750, CVE-2015-5751, CVE-2015-5753, CVE-2015-5754, CVE-2015-5755, CVE-2015-5756, CVE-2015-5757, CVE-2015-5758, CVE-2015-5761, CVE-2015-5763, CVE-2015-5768, CVE-2015-5771, CVE-2015-5772, CVE-2015-5773, CVE-2015-5774, CVE-2015-5775, CVE-2015-5776, CVE-2015-5777, CVE-2015-5778, CVE-2015-5779, CVE-2015-5781, CVE-2015-5782, CVE-2015-5783, CVE-2015-5784

BID: 36381, 58203, 58207, 62741, 64194, 65179, 65379, 65721, 65997, 67233, 69742, 69748, 70089, 70644, 70988, 71150, 71153, 71468, 71639, 71656, 71657, 71701, 71964, 72538, 72540, 72542, 72543, 72649, 72981, 73040, 73041, 73357, 73431, 74174, 74204, 74239, 74240, 74299, 74300, 74301, 74303, 74408, 74700, 74703, 74902, 74903, 74904, 75056, 75103, 75154, 75156, 75157, 75158, 75161, 75704, 75963, 75964, 75965, 75990, 76337, 76338, 76339, 76340, 76341, 76342, 76343, 76344

APPLE-SA: APPLE-SA-2015-08-13-2