There's no such thing as a stupid question, but they're the easiest to answer.
JoinTour
Login
 
Tag Cloud
acer black screen blue screen blue screen of death boot computer connection crash css dell display driver drivers email error firefox firefox 3 game hard drive internet internet explorer itunes laptop malware monitor network networking nvidia outlook outlook 2003 outlook express partition password printer problem problems router security slow software sound startup trojan usb video virus vista windows windows xp wireless
Apple Macintosh
Search
Search in:
 
Advanced Search
Tech Support Guy Forums > Operating Systems > Apple Macintosh >
Apple MacOS X BOMArchiveHelper Directory Traversal Vulnerability


HELLO AND WELCOME! Before you can post your question, you'll have to register -- it's completely free! Click here to join today! We highly recommend that you print a copy of our Guide for New Members. Enjoy!

Closed Thread
 
Thread Tools
eddie5659's Avatar
Computer Specs
Moderator with 18,505 posts.
 
Join Date: Mar 2001
Location: Bradford, England
05-Mar-2006, 06:46 PM #1
Exclamation Apple MacOS X BOMArchiveHelper Directory Traversal Vulnerability
Hiya

Sticking this for a week

This has a few updates, but these are the ones they address:

Impact: Multiple security issues in PHP 4.4
Available for: Mac OS X v10.3.9, Mac OS X Server v10.3.9, Mac OS X v10.4.5, Mac OS X Server v10.4.5

Impact: Malicious network servers may cause a denial of service or arbitrary code execution
Available for: Mac OS X v10.3.9, Mac OS X Server v10.3.9, Mac OS X v10.4.5, Mac OS X Server v10.4.5

Impact: Directory traversal may occur while unpacking archives with BOM
Available for: Mac OS X v10.3.9, Mac OS X Server v10.3.9, Mac OS X v10.4.5, Mac OS X Server v10.4.5

Impact: Malicious local users may create and manipulate files as root
Available for: Mac OS X v10.3.9, Mac OS X Server v10.3.9, Mac OS X v10.4.5, Mac OS X Server v10.4.5

Impact: FileVault may permit access to files during when it is first enabled
Available for: Mac OS X v10.3.9, Mac OS X Server v10.3.9, Mac OS X v10.4.5, Mac OS X Server v10.4.5

Impact: Remote denial of service against VPN connections
Available for: Mac OS X v10.3.9, Mac OS X Server v10.3.9, Mac OS X v10.4.5, Mac OS X Server v10.4.5

Impact: Attackers may cause crashes or arbitrary code execution depending upon the application
Available for: Mac OS X v10.4.5, Mac OS X Server v10.4.5

Impact: Download Validation fails to warn about unsafe file types
Available for: Mac OS X v10.4.5, Mac OS X Server v10.4.5

Impact: Perl programs may fail to drop privileges
Available for: Mac OS X v10.3.9, Mac OS X Server v10.3.9

Impact: Authenticated users may cause an rsync server to crash or execute arbitrary code
Available for: Mac OS X v10.4.5, Mac OS X Server v10.4.5

Impact: Viewing a maliciously-crafted web page may result in arbitrary code execution
Available for: Mac OS X v10.3.9, Mac OS X Server v10.3.9, Mac OS X v10.4.5, Mac OS X Server v10.4.5

Impact: Viewing a malicious web page may cause arbitrary code execution
Available for: Mac OS X v10.3.9, Mac OS X Server v10.3.9, Mac OS X v10.4.5, Mac OS X Server v10.4.5

Impact: Remote web sites can redirect to local resources, allowing JavaScript to execute in the local domain
Available for: Mac OS X v10.3.9, Mac OS X Server v10.3.9, Mac OS X v10.4.5, Mac OS X Server v10.4.5

Impact: Viewing a malicious web site may result in arbitrary code execution
Available for: Mac OS X v10.3.9, Mac OS X Server v10.3.9, Mac OS X v10.4.5, Mac OS X Server v10.4.5

Impact: Subscriptions to malicious RSS content can lead to cross-site scripting
Available for: Mac OS X v10.4.5, Mac OS X Server v10.4.5





http://docs.info.apple.com/article.html?artnum=303382

Regards

eddie
__________________
Just go with the flow, like a twig on the shoulders of a mighty stream
Closed Thread

THIS THREAD HAS EXPIRED.
Are you having the same problem? We have volunteers ready to answer your question, but first you'll have to join for free. Need help getting started? Check out our Welcome Guide.


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
WELCOME TO TECH SUPPORT GUY! Are you looking for the solution to your computer problem? Join our site today to ask your question -- for free! Our site is run completely by volunteers who help people like you solve computer problems. See our Welcome Guide to get started.



Thread Tools


You Are Using:
Server ID
Advertisements do not imply our endorsement of that product or service.
All times are GMT -4. The time now is 05:08 PM.
Copyright © 1996 - 2008 TechGuy, Inc. All rights reserved.
Powered by vBulletin, Copyright © 2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.1.0
Powered by Cermak Technologies, Inc.