| PROBLEM: | Apple released a security update that provides fixes for several security issues. One involves a library that is linked to by a large number of system binaries. |
| PLATFORM: | Mac OS X 10.3.8 Mac OS X Server 10.3.8 |
| DAMAGE: | Various security issues were addressed. These issues have several impacts, including denial of service, buffer overflows, local privilege escalation, and possible remote code execution. |
| SOLUTION: | Apply the available security updates. |
| VULNERABILITY ASSESSMENT: |
The risk is MEDIUM. The severity of the possible vulnerabilities depends on which applications are being used on the system. For example, the system binaries problem allows a local user to gain root privileges. |
| LINKS: | |
| CIAC BULLETIN: | http://www.ciac.org/ciac/bulletins/p-156.shtml |
| ORIGINAL BULLETIN: | http://docs.info.apple.com/article.html?artnum=301061 |
| CVE/CAN: | http://www.cve.mitre.org/cgi-bin/cvename.cgi?name= CAN-2005-0340, CAN-2005-0715, CAN-2005-0713, CAN-2005-0716, CAN-2004-1011, CAN-2004-1012, CAN-2004-1013, CAN-2004-1015, CAN-2004-1067, CAN-2002-1347, CAN-2004-0884, CAN-2005-0712, CAN-2005-0202, CAN-2005-0234 |
[***** Start Apple Security Update 2005-003 *****] Visit Apple's Website directly for their published information: http://docs.info.apple.com/article.html?artnum=301061 [***** End Apple Security Update 2005-003 *****]
Voice: +1 925-422-8193 (7 x 24)
FAX: +1 925-423-8002
STU-III: +1 925-423-2604
E-mail: ciac@ciac.org
World Wide Web: http://www.ciac.org/
Anonymous FTP: ftp.ciac.org