Subscribe via feed.

Apple Security Advisory 2014-10-16-3

Posted by deepcore under Apple (No Respond)

Apple Security Advisory 2014-10-16-3 – OS X Server 4.0 is now available and addresses vulnerabilities in BIND, Wiki server, Xcode server, PostgreSQL, and various other software.

Tags: , ,

Apple Security Advisory 2014-10-16-4

Posted by deepcore under Apple (No Respond)

Apple Security Advisory 2014-10-16-4 – OS X Server 3.2.2 is now available and addresses the SSL 3.0 Poodle bug. There are known attacks on the confidentiality of SSL 3.0 when a cipher suite uses a block cipher in CBC mode. An attacker could force the use of SSL 3.0, even when the server would support […]

Tags: , ,

Apple Security Advisory 2014-10-16-5

Posted by deepcore under Apple (No Respond)

Apple Security Advisory 2014-10-16-5 – OS X Server 2.2.5 is now available and addresses the SSL 3.0 Poodle bug. There are known attacks on the confidentiality of SSL 3.0 when a cipher suite uses a block cipher in CBC mode. An attacker could force the use of SSL 3.0, even when the server would support […]

Tags: , ,

Apple Security Advisory 2014-10-16-6

Posted by deepcore under Apple (No Respond)

Apple Security Advisory 2014-10-16-6 – iTunes 12.0.1 is now available and addresses 83 vulnerabilities.

Tags: , ,

Apple Security Advisory 2014-09-17-3

Posted by deepcore under Apple (No Respond)

Apple Security Advisory 2014-09-17-3 – OS X Mavericks 10.9.5 and Security Update 2014-004 are now available and address PHP code execution, Bluetooth API validation, PDF handling, and various other vulnerabilities.

Tags: , ,

Apple Security Advisory 2014-09-17-4

Posted by deepcore under Apple (No Respond)

Apple Security Advisory 2014-09-17-4 – Safari 6.2 and Safari 7.1 are now available and address credential interception, arbitrary code execution, and data browsing vulnerabilities.

Tags: , ,

Apple Security Advisory 2014-09-17-5

Posted by deepcore under Apple (No Respond)

Apple Security Advisory 2014-09-17-5 – OS X Server 3.2.1 is now available and addresses arbitrary SQL execution, arbitrary javascript execution, and multiple vulnerabilities in PostgreSQL.

Tags: , ,

Apple Security Advisory 2014-09-17-6

Posted by deepcore under Apple (No Respond)

Apple Security Advisory 2014-09-17-6 – OS X Server 2.2.3 is now available and addresses an arbitrary SQL query execution vulnerability.

Tags: , ,

Apple Security Advisory 2014-09-17-7

Posted by deepcore under Apple (No Respond)

Apple Security Advisory 2014-09-17-7 – Xcode 6.0.1 is now available and addresses a denial of service vulnerability.

Tags: , ,

Apple Foundation NSXMLParser XML eXternal Entity (XXE)

Posted by deepcore under Apple (No Respond)

In May 2014, VSR identified a vulnerability in versions 7.0 and 7.1 of the iOS SDK whereby the NSXMLParser class, resolves XML External Entities by default despite documentation which indicates otherwise. In addition, settings to change the behavior of XML External Entity resolution appears to be non-functional. This vulnerability, commonly known as XXE (XML eXternal […]

Tags: , ,