Uočen je i otklonjen sigurnosni nedostatak vezan uz Apple TV 5.0 koji su potencijalni napadači mogli iskoristiti za izvođenje napada uskraćivanjem usluge i/ili pokretanje proizvoljnog programskog koda.
Paket:
Apple TV 5.x
Operacijski sustavi:
Apple Mac OS X 10, Apple Mac OS X 10.1, Apple Mac OS X 10.2, Apple Mac OS X 10.3, Apple Mac OS X 10.4, Apple Mac OS X 10.5, Apple Mac OS X 10.6, Apple Mac OS X 10.7
Do propusta dolazi uslijed cjelobrojnog prepisivanja u biblioteci libresolv.
Posljedica:
Propust je moguće iskoristiti za DoS (eng. Denial of Service) napad ili izvršavanje proizvoljnog programskog koda podmetanjem posebno oblikovanih DNS podataka.
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
APPLE-SA-2012-03-07-3 Apple TV 5.0
Apple TV 5.0 is now available and addresses the following:
Apple TV
Available for: Apple TV (2nd generation)
Impact: Applications that use the libresolv library may be
vulnerable to an unexpected application termination or arbitrary code
execution
Description: An integer overflow existed in the handling of DNS
resource records, which may lead to heap memory corruption.
CVE-ID
CVE-2011-3453 : Ilja van Sprundel of IOActive
Installation note:
Apple TV will periodically check for software updates. Alternatively,
you may manually check for software updates by selecting
"Settings -> General -> Update Software".
To check the current version of software, select
"Settings -> General -> About".
Information will also be posted to the Apple Security Updates
web site: http://support.apple.com/kb/HT1222
This message is signed with Apple's Product Security PGP key,
and details are available at:
https://www.apple.com/support/security/pgp/
-----BEGIN PGP SIGNATURE-----
Version: GnuPG/MacGPG2 v2.0.16 (Darwin)
iQEcBAEBAgAGBQJPV6OMAAoJEGnF2JsdZQeetlIH/RFQxn1BAG0kUhLhEiEQ0cAd
y+oYBHg9IOWLgEuPy6APrk7o+vJcrv7EmzzVuFy83PisRgWvb5muJEp0wHmFjDe1
j0Ex6CbppPGNa/MppCMKjHXrGSD4jnCakssojk+ADSPPXJrePUfBf5sh856IOl2k
u8HDq91ArSSlAZV96j1gvEEVTidf6ZNOn9EiSPEEPPImP8Ay2KJbEaMG5DWF5bae
z9n+byjYv3k+hhCD4XXd/42DYIH71D7uB7wddsjNP7PC+fiHB5l33hrapq0OCUTe
8ZkKHIfzOoZN7B+Q/6zy+iixRRCyeLmLsQdGWwP5IPuRVsLDJ4uESSEPgiagd6c=
=BjXf
-----END PGP SIGNATURE-----
_______________________________________________
Do not post admin requests to the list. They will be ignored.
Security-announce mailing list (Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.)
Help/Unsubscribe/Update your Subscription:
https://lists.apple.com/mailman/options/security-announce/advisory%40lss.hr
This email sent to Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
Posljednje sigurnosne preporuke