U radu operacijskog sustava Apple Mac OS X uočen je sigurnosni propust kojeg udaljeni napadač može iskoristiti za izvođenje DoS (eng. Denial of Service) napada.
Paket:
Apple Mac OS X 10.7.x
Operacijski sustavi:
Apple Mac OS X 10.7
Problem:
pogreška u programskoj komponenti
Iskorištavanje:
udaljeno
Posljedica:
uskraćivanje usluga (DoS)
Rješenje:
programska zakrpa proizvođača
Izvorni ID preporuke:
SA46707
Izvor:
Secunia
Problem:
Propust je uzrokovan pogreškom u Mail aplikaciji.
Posljedica:
Napadaču omogućuje izvođenje DoS napada putem email poruka koje sadrže veliku količinu MIME privitaka (eng. attachment).
Rješenje:
Budući da zasad nisu dostupne zakrpe za otklanjanje spomenutog problema, korisnicima se savjetuje korištenje drugog klijenta za brisanje zlonamjernih email poruka.
Apple Mac OS X Mail MIME Attachments Denial of Service Weakness
Secunia Advisory SA46707
Release Date 2011-11-08
Criticality level Not criticalNot critical
Impact DoS
Where From remote
Authentication level Available in Customer Area
Report reliability Available in Customer Area
Solution Status Unpatched
Systems affected Available in Customer Area
Approve distribution Available in Customer Area
Remediation status Secunia VIM
Operating System
Apple Macintosh OS X
Secunia CVSS Score Available in Customer Area
CVE Reference(s) No CVE references.
Description
A weakness has been discovered in Apple Mac OS X, which can be exploited by malicious people to cause a DoS (Denial of Service).
The weakness is caused due to an error in the Mail application when processing certain emails, which can be exploited to crash the application via emails containing a large amount of MIME attachments.
The weakness is confirmed in version 5.1 (1251/1251.1) on Mac OS X 10.7.2.
Solution
Use another email client to delete malicious emails.
Provided and/or discovered by
shebang42
Original Advisory
http://archives.neohapsis.com/archives/bugtraq/2011-10/0215.html
Posljednje sigurnosne preporuke