Subscribe via feed.
Posts under OSX security tools

Zero Day Initiative Advisory 11-230

Posted by deepcore under Apple, exploit, OSX security tools (No Respond)

Zero Day Initiative Advisory 11-230 – This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apple Quicktime. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the way Quicktime handles Apple Lossless Audio Codec streams.

Tags: , , ,

Zero Day Initiative Advisory 11-229

Posted by deepcore under Apple, exploit, OSX security tools (No Respond)

Zero Day Initiative Advisory 11-229 – This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apple QuickTime. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within how the application parses a specially formatted RIFF WAV file

Tags: , , , ,

Zero Day Initiative Advisory 11-228

Posted by deepcore under Apple, exploit, OSX security tools (No Respond)

Zero Day Initiative Advisory 11-228 – This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apple Safari on Windows and multiple applications on OSX.

Tags: , ,

Apple Security Advisory 2011-06-28

Posted by deepcore under Apple, OSX security tools, Security (No Respond)

Apple Security Advisory 2011-06-28-1 – Multiple vulnerabilities exist in Java 1.6.0_24, the most serious of which may allow an untrusted Java applet to execute arbitrary code outside the Java sandbox. Visiting a web page containing a maliciously crafted untrusted Java applet may lead to arbitrary code execution with the privileges of the current user. These issues are addressed by updating to Java version 1.6.0_26.

Tags: , ,

Secunia Security Advisory 45084

Posted by deepcore under Apple, exploit, OSX security tools, Security (No Respond)

Secunia Security Advisory – Apple has issued an update for Java for Mac OS X. This fixes multiple vulnerabilities, which can be exploited by malicious people to disclose potentially sensitive information, manipulate certain data, cause a DoS (Denial of Service), and compromise a vulnerable system.

Tags: ,

Secunia Security Advisory 45054

Posted by deepcore under Apple, OSX security tools, Security (No Respond)

Secunia Security Advisory – Apple has issued a security update for Mac OS X, which fixes multiple vulnerabilities.

Tags: , ,

Viper Auto-Rooting Script

Posted by deepcore under Apple, OSX security tools (No Respond)

This is the Viper auto-rooting script that is written for Linux, SunOS, Mac OS X, and FreeBSD.

Tags: ,

Zero Day Initiative Advisory 11-190

Posted by deepcore under Apple, exploit, OSX security tools (No Respond)

Zero Day Initiative Advisory 11-190 – This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of the Oracle Java Runtime running on OSX or Linux. This vulnerability does not affect java running on Windows.

Tags: , , ,

iDEFENSE Security Advisory 2011-06-01.1

Posted by deepcore under Apple, exploit, OSX security tools, Security (No Respond)

iDefense Security Advisory 06.01.11 – Remote exploitation of a design error within Cisco Systems Inc’s AnyConnect VPN client allows attackers to execute arbitrary code with the privileges of a user running Internet Explorer.

Tags: , ,

libc/fnmatch(3) Denial Of Service

Posted by deepcore under Apple, OSX security tools, software (No Respond)

Multiple vendors libc/fnmatch(3) suffer from a denial of service vulnerability. Affected software includes Apache 2.2.17, NetBSD 5.1, OpenBSD 4.8, FreeBSD, Mac OS X 10.6, and Sun Solaris 10. Apache proof of concept is included.

Tags: , , ,