Skip Navigation

  • Home
  • Contact us
  • FAQ
  • Glossary
  • Public key
  • Sitemap
  • Cymraeg
  • What's new
CPNI - Centre for the Protection of National Infastructure

Advanced search

  • About CPNI
  • The threats
  • Security planning
  • Methods of attack
  • Protecting your assets
  • Products and services
    • CSIRTUK advisories
      • Advisories archive
    • General protective security publications
    • InfoSec briefings
    • InfoSec technical notes
    • InfoSec vulnerability disclosures
    • Good practice guidelines
    • Viewpoints
    • Information exchanges
    • Risk Management Delivery Group
  • Research
Home > Products and services > CSIRTUK advisories > Advisories archive > March 2007 > Apple Security Advisory: APPLE-SA-2007-02-15 - Security Update 2007-002

March 2007

Apple Security Advisory: APPLE-SA-2007-02-15 - Security Update 2007-002

ID: 73
Ref: 015/2007
Date: 07 March 2007:18:36:44
Version: 1

Title: Apple Security Advisory: APPLE-SA-2007-02-15 - Security Update 2007-002
Abstract: A buffer overflow exists in the handling of volume names. By enticing a user to mount a malicious disk image, an attacker could trigger this issue, which may lead to an application crash or arbitrary code execution.
Vendors affected: Apple
Operating systems affected: Apple

A buffer overflow exists in Finder's handling of volume names. By enticing a user to mount a malicious disk image, an attacker could trigger this issue, which may lead to an application crash or arbitrary code execution. A proof of concept for this issue has been published on the Month of Apple Bugs web site (MOAB-09-01-2007). This update addresses the issue by performing additional validation of disk images. This issue does not affect systems prior to Mac OS X v10.4. Credit to Kevin Finisterre of DigitalMunition for reporting this issue.

- -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

APPLE-SA-2007-02-15 Security Update 2007-002

Security Update 2007-002 is now available and addresses the following
issues:

Finder
CVE-ID: CVE-2007-0197
Available for: Mac OS X v10.4.8, Mac OS X Server v10.4.8
Impact: Mounting a maliciously-crafted disk image may lead to an application crash or arbitrary code execution
Description: A buffer overflow exists in Finder's handling of volume names. By enticing a user to mount a malicious disk image, an attacker could trigger this issue, which may lead to an application crash or arbitrary code execution. A proof of concept for this issue has been published on the Month of Apple Bugs web site (MOAB-09-01-2007). This update addresses the issue by performing additional validation of disk images. This issue does not affect systems prior to Mac OS X v10.4. Credit to Kevin Finisterre of DigitalMunition for reporting this issue.

iChat
CVE-ID: CVE-2007-0614, CVE-2007-0710
Available for: Mac OS X v10.3.9, Mac OS X Server v10.3.9, Mac OS X v10.4.8, Mac OS X Server v10.4.8
Impact: Attackers on the local network may be able to cause iChat to crash
Description: A null pointer dereference in iChat's Bonjour message handling could allow a local network attacker to cause an application crash. A proof of concept for this issue in Mac OS X v10.4 has been published on the Month of Apple Bugs web site (MOAB-29-01-2007). This update addresses the issues by performing additional validation of Bonjour messages.

iChat
CVE-ID: CVE-2007-0021
Available for: Mac OS X v10.3.9, Mac OS X Server v10.3.9, Mac OS X v10.4.8, Mac OS X Server v10.4.8
Impact: Visiting malicious websites may lead to an application crash or arbitrary code execution
Description: A format string vulnerability exists in the iChat AIM URL handler. By enticing a user to access a maliciously-crafted AIM URL, an attacker can trigger the overflow, which may lead to an application crash or arbitrary code execution. A proof of concept for this issue has been published on the Month of Apple Bugs web site (MOAB-20-01-2007). This update addresses the issue by performing additional validation of AIM URLs.

UserNotification
CVE-ID: CVE-2007-0023
Available for: Mac OS X v10.3.9, Mac OS X Server v10.3.9, Mac OS X v10.4.8, Mac OS X Server v10.4.8
Impact: Malicious local users may be able to obtain system privileges
Description: The UserNotificationCenter process runs with elevated privileges in the context of a local user. This may allow a malicious local user to overwrite or modify system files. A program that triggers this issue has been published on the Month of Apple Bugs web site (MOAB-22-01-2007). This update addresses the issue by having UserNotificationCenter drop its group privileges immediately after launching.

Security Update 2007-002 may be obtained from the Software Update pane in System Preferences, or Apple's Software Downloads web
site:
http://www.apple.com/support/downloads/

For Mac OS X v10.4.8 (PowerPC)
The download file is named: "SecUpd2007-002Ti.dmg"
Its SHA-1 digest is: 79da4e0f61288277f9896e761903abf748d2dc21

For Mac OS X v10.4.8 (Intel)
The download file is named: "SecUpd2007-002Univ.dmg"
Its SHA-1 digest is: 9a4b97853ac05ff407a8b8fe0906d916e219648b

For Mac OS X v10.3.9
The download file is named: "SecUpd2007-002Pan.dmg"
Its SHA-1 digest is: 81199248bf7218d8788663153131ab51d31320a1

Information will also be posted to the Apple Product Security web site:
http://docs.info.apple.com/article.html?artnum=61798

This message is signed with Apple's Product Security PGP key, and details are available at:
http://www.apple.com/support/security/pgp/

- -----BEGIN PGP SIGNATURE-----
Version: PGP Desktop 9.0.3 (Build 2932)

iQEVAwUBRdSUVYmzP5/bU5rtAQhWywgAn97GfRUyIFuBPsx37RNG1XCo5swnVY3u
agGCzAyXtEj5D/AiyVzPLrT5Lmb2I78grI6wJDocB5k8g1HCQQsvJoMneN1iAtMH
ekwyicx5ZP0Fwh/JYBIQjcWgpVm5S5cA+A4ZOjsODU0xT+jl9SxjVZe62y95eTF0
fK/LNvKQkxpUYHbAJ5mU9JC8dUQ/m9dGlHt3nRM82or0zJNxSa3YvhSLaEXs2HBF
Zynt4xfrFXFuw9YJR2R+K7CsDypTbCbN+oL0cp4RfFdJVfZ3RVIZrCDKGjXElP3y
3tmAaP6NXJ7A1YK5jB+k30l2N+dh5yDW27AdH/17IBScUvYiauBpmQ==
=duIn
- -----END PGP SIGNATURE-----


______________________________________________________________________________

CPNI values your feedback.

1. Which of the following most reflects the value of the advisory to you?
(Place an 'X' next to your choice)

Very useful:__ Useful:__ Not useful:__

2. If you did not find it useful, why not?


3. Any other comments? How could we improve our advisories?


Thank you for your contribution.
______________________________________________________________________________

CPNI wishes to acknowledge the contributions of Apple for the information contained in this advisory.
______________________________________________________________________________
  • Accessibility |
  • Terms and conditions |
  • Privacy statement |
  • Data protection act |
  • Freedom of information |