Vulnerabilities > CVE-2007-2399 - Unspecified vulnerability in Apple mac OS X and mac OS X Server
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN apple
nessus
Summary
WebKit in Apple Mac OS X 10.3.9, 10.4.9 and later, and iPhone before 1.0.1 performs an "invalid type conversion", which allows remote attackers to execute arbitrary code via unspecified frame sets that trigger memory corruption.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
OS | 5 |
Nessus
NASL family | MacOS X Local Security Checks |
NASL id | MACOSX_SECUPD2007-006.NASL |
description | The remote host is running a version of Mac OS X 10.4 or 10.3 which does not have the security update 2007-006 applied. This update fixes security flaws in WebKit and WebCore which might allow an attacker to execute arbitrary code on the remote host. To execute arbitrary code, an attacker would need to lure a user of the remote host into visiting a malicious website containing a specially malformed html file which would trigger a buffer overflow. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 25566 |
published | 2007-06-25 |
reporter | This script is Copyright (C) 2007-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/25566 |
title | Mac OS X Multiple Vulnerabilities (Security Update 2007-006) |
code |
|
Seebug
bulletinFamily | exploit |
description | CVE(CAN) ID: CVE-2007-2399,CVE-2007-2400,CVE-2007-2401,CVE-2007-3742,CVE-2007-3944 iPhone是蒴果公司开发的智能手机。 iPhone的实现上存在多个安全漏洞,可导致恶意操作浏览器或信息泄露。 具体漏洞条目如下: * CVE-2007-2400 Safari处理JavsScript的实现上存在漏洞,远程攻击者可能利用此漏洞绕过同源策略非授权操作其他网页。 * CVE-2007-3944 Safari的JavaScript引擎使用的PCRE库实现上存在堆溢出漏洞,远程攻击者可能利用此漏洞通过诱使用户访问恶意网页控制用户系统。 * CVE-2007-2401 WebCore软件包的XMLHttpRequest处理HTTP请求头时存在漏洞,导致跨站脚本执行。 * CVE-2007-3742 WebKit软件包实现上存在漏洞,可能导致浏览器中的域名欺骗。 * CVE-2007-2399 WebKit软件包在生成网页时处理无效的类型转换存在漏洞,远程攻击者可能利用此漏洞导致软件崩溃或执行任意指令。 Apple iPhone 1.0.1 目前厂商已经发布了升级补丁以修复这个安全问题,请到厂商的主页下载: <a href="http://docs.info.apple.com/article.html?artnum=306173" target="_blank">http://docs.info.apple.com/article.html?artnum=306173</a> |
id | SSV:2063 |
last seen | 2017-11-19 |
modified | 2007-08-02 |
published | 2007-08-02 |
reporter | Root |
title | Apple iPhone多个安全漏洞 |
References
- http://docs.info.apple.com/article.html?artnum=305759
- http://docs.info.apple.com/article.html?artnum=305759
- http://docs.info.apple.com/article.html?artnum=306173
- http://docs.info.apple.com/article.html?artnum=306173
- http://lists.apple.com/archives/Security-announce/2007/Jun/msg00003.html
- http://lists.apple.com/archives/Security-announce/2007/Jun/msg00003.html
- http://osvdb.org/36130
- http://osvdb.org/36130
- http://osvdb.org/36450
- http://osvdb.org/36450
- http://secunia.com/advisories/25786
- http://secunia.com/advisories/25786
- http://secunia.com/advisories/26287
- http://secunia.com/advisories/26287
- http://www.kb.cert.org/vuls/id/389868
- http://www.kb.cert.org/vuls/id/389868
- http://www.securityfocus.com/bid/24597
- http://www.securityfocus.com/bid/24597
- http://www.securitytracker.com/id?1018281
- http://www.securitytracker.com/id?1018281
- http://www.vupen.com/english/advisories/2007/2296
- http://www.vupen.com/english/advisories/2007/2296
- http://www.vupen.com/english/advisories/2007/2316
- http://www.vupen.com/english/advisories/2007/2316
- http://www.vupen.com/english/advisories/2007/2731
- http://www.vupen.com/english/advisories/2007/2731
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35019
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35019