| PROBLEM: | There are several security vulnerabilities in AirPort: 1) Two separate stack buffer overflows exist in the AirPort wireless driver's handling of malformed frames; 2) A heap buffer overflow exists in the AirPort wireless driver's handling of scan cache updates; and 3) An interger overflow exists in the AirPort wireless driver's API for third-party wireless software. |
| PLATFORM: | Mac OS X v10.3.9 & v10.4.7 Mac OS X Server 10.3.9 & v10.4.7 |
| DAMAGE: | Attackers on the wireless network may cause arbitrary code execution, may cause system crashes, or privilege elevation. |
| SOLUTION: | Upgrade to the appropriate version. |
| VULNERABILITY ASSESSMENT: |
The risk is HIGH. May cause arbitrary code execution. |
| LINKS: | |
| CIAC BULLETIN: | http://www.ciac.org/ciac/bulletins/q-323.shtml |
| ORIGINAL BULLETIN: | AirPort Update 2006-001 and Apple Security Update 2006-005 |
| http://docs.info.apple.com/article.html?artnum=304420 | |
| ADDITIONAL LINKS: | US-CERT Vulnerability Note VU#897796 |
| http://www.kb.cert.org/vuls/id/867796 | |
| http://www.kb.cert.org/vuls/id/589540 | |
| http://www.kb.cert.org/vuls/id/563492 | |
| CVE: | CVE-2006-3507 CVE-2006-3508 CVE-2006-3509 |
[***** Start 2006-004 *****] Please visit Apple's website to view their QuickTime Security Advisory: http://docs.info.apple.com/article.html?artnum=304420 [***** End 2006-004 *****]
Voice: +1 925-422-8193 (7 x 24)
FAX: +1 925-423-8002
STU-III: +1 925-423-2604
E-mail: ciac@ciac.org
World Wide Web: http://www.ciac.org/
Anonymous FTP: ftp.ciac.org