Vulnerabilities > CVE-2008-0040 - Resource Management Errors vulnerability in Apple mac OS X 10.5/10.5.1

047910
CVSS 10.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
apple
CWE-399
critical
nessus

Summary

Unspecified vulnerability in NFS in Apple Mac OS X 10.5 through 10.5.1 allows remote attackers to cause a denial of service (system shutdown) or execute arbitrary code via unknown vectors related to mbuf chains that trigger memory corruption.

Vulnerable Configurations

Part Description Count
OS
Apple
2

Common Weakness Enumeration (CWE)

Nessus

  • NASL familyMacOS X Local Security Checks
    NASL idMACOSX_10_5_2.NASL
    descriptionThe remote host is running a version of Mac OS X 10.5.x that is prior to 10.5.2. Mac OS X 10.5.2 contains several security fixes for a number of programs.
    last seen2020-06-01
    modified2020-06-02
    plugin id30255
    published2008-02-12
    reporterThis script is Copyright (C) 2008-2018 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/30255
    titleMac OS X 10.5.x < 10.5.2 Multiple Vulnerabilities
  • NASL familyMacOS X Local Security Checks
    NASL idMACOSX_SECUPD2008-001.NASL
    descriptionThe remote host is running a version of Mac OS X 10.4 that does not have the security update 2008-001 applied. This update contains several security fixes for a number of programs.
    last seen2020-06-01
    modified2020-06-02
    plugin id30254
    published2008-02-12
    reporterThis script is Copyright (C) 2008-2018 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/30254
    titleMac OS X Multiple Vulnerabilities (Security Update 2008-001)

Seebug

bulletinFamilyexploit
descriptionBUGTRAQ ID: 27736 CVE(CAN) ID: CVE-2008-0037,CVE-2008-0038,CVE-2008-0039,CVE-2008-0040,CVE-2008-0041,CVE-2008-0042 Mac OS X是苹果家族机器所使用的操作系统。 Apple 2008-001安全更新修复了Mac OS X中的多个安全漏洞,远程或本地攻击者可能利用这些漏洞造成多种威胁。 CVE-2008-0037 Mac OS X中的X11服务器没有正确地读取Allow connections from network client首选项,即使已经关闭了该选项X11服务器仍会允许网络客户端连接。 CVE-2008-0038 Launch服务是一个API,用于以类似于Finder或Dock的方式打开应用程序、文档文件或URL。如果已从系统中卸载应用程序的话,用户会认为不会再加载,但如果Time Machine备份中存在该应用程序的话,即使已经卸载Launch服务仍允许将其加载。 CVE-2008-0039 Mail处理file:// URL方式中的错误允许当用户点击消息中URL时未经任何警告便加载任意应用程序。 CVE-2008-0040 NFS处理mbuf链表的方式存在内存破坏漏洞。如果将系统用作NFS客户端或服务器的话,恶意的NFS服务器或客户端就可以导致系统意外关闭或执行任意指令。 CVE-2008-0041 在设置管理Web内容时,如果没有阻断站点的话Parental Control会联络www.apple.com,这允许远程用户判断机器是否在运行Parental Control。 CVE-2008-0042 Terminal.app处理URL主题的方式存在输入验证错误,如果用户受骗访问了特制的Web页面的话,攻击者就可以以可控的命令行参数加载应用程序,这可能导致执行任意指令。 Apple Mac OS X &lt; 10.5.2 Apple MacOS X Server &lt; 10.5.2 厂商补丁: Apple ----- 目前厂商已经发布了升级补丁以修复这个安全问题,请到厂商的主页下载: <a href=http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=17381&amp;cat=1&amp;platform=osx&amp;method=sa/SecUpd2008-001PPC.dmg target=_blank>http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=17381&amp;cat=1&amp;platform=osx&amp;method=sa/SecUpd2008-001PPC.dmg</a> <a href=http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=17382&amp;cat=57&amp;platform=osx&amp;method=sa/SecUpd2008-001Univ.dmg target=_blank>http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=17382&amp;cat=57&amp;platform=osx&amp;method=sa/SecUpd2008-001Univ.dmg</a>
idSSV:2916
last seen2017-11-19
modified2008-02-21
published2008-02-21
reporterRoot
titleApple Mac OS X 2008-001更新修复多个安全漏洞