MacOS X IPSec端口安全策略可绕过漏洞

漏洞信息详情

MacOS X IPSec端口安全策略可绕过漏洞

漏洞简介

Mac OS X是一款使用在Mac机器上的操作系统,基于BSD系统。
MacOS X在使能IPSec时不正确处理部分通信,远程攻击者可以利用这个漏洞未授权访问部分敏感服务。
问题是Mac OS X 10.2.6版本在使用IPSec时,那些由端口进行匹配的安全策略不正确处理部分通信,可导致攻击者绕过安全限制访问部分敏感服务。

漏洞公告

厂商补丁:
Apple
—–
目前厂商已经发布了升级补丁以修复这个安全问题,请到厂商的主页下载:

Apple MacOS X Server 10.0:

Apple Upgrade MacOS X Server 10.2.6

http://www.apple.com/macosx/server” target=”_blank”>
http://www.apple.com/macosx/server

Apple MacOS X 10.0:

Apple Upgrade MacOS X 10.2.6

http://www.apple.com/macosx/” target=”_blank”>
http://www.apple.com/macosx/

Apple MacOS X 10.0.1:

Apple Upgrade MacOS X 10.2.6

http://www.apple.com/macosx/” target=”_blank”>
http://www.apple.com/macosx/

Apple MacOS X 10.0.2:

Apple Upgrade MacOS X 10.2.6

http://www.apple.com/macosx/” target=”_blank”>
http://www.apple.com/macosx/

Apple MacOS X 10.0.3:

Apple Upgrade MacOS X 10.2.6

http://www.apple.com/macosx/” target=”_blank”>
http://www.apple.com/macosx/

Apple MacOS X 10.0.4:

Apple Upgrade MacOS X 10.2.6

http://www.apple.com/macosx/” target=”_blank”>
http://www.apple.com/macosx/

Apple MacOS X 10.1:

Apple Upgrade MacOS X 10.2.6

http://www.apple.com/macosx/” target=”_blank”>
http://www.apple.com/macosx/

Apple MacOS X 10.1.1:

Apple Upgrade MacOS X 10.2.6

http://www.apple.com/macosx/” target=”_blank”>
http://www.apple.com/macosx/

Apple MacOS X 10.1.2:

Apple Upgrade MacOS X 10.2.6

http://www.apple.com/macosx/” target=”_blank”>
http://www.apple.com/macosx/

Apple MacOS X 10.1.3:

Apple Upgrade MacOS X 10.2.6

http://www.apple.com/macosx/” target=”_blank”>
http://www.apple.com/macosx/

Apple MacOS X 10.1.4:

Apple Upgrade MacOS X 10.2.6

http://www.apple.com/macosx/” target=”_blank”>
http://www.apple.com/macosx/

Apple MacOS X 10.1.5:

Apple Upgrade MacOS X 10.2.6

http://www.apple.com/macosx/” target=”_blank”>
http://www.apple.com/macosx/

Apple MacOS X 10.2:

Apple Upgrade MacOS X 10.2.6

http://www.apple.com/macosx/” target=”_blank”>
http://www.apple.com/macosx/

Apple MacOS X Server 10.2:

Apple Upgrade MacOS X Server 10.2.6

http://www.apple.com/macosx/server” target=”_blank”>
http://www.apple.com/macosx/server

Apple MacOS X 10.2.1:

Apple Upgrade MacOS X 10.2.6

http://www.apple.com/macosx/” target=”_blank”>
http://www.apple.com/macosx/

Apple MacOS X Server 10.2.1:

Apple Upgrade MacOS X Server 10.2.6

http://www.apple.com/macosx/server” target=”_blank”>
http://www.apple.com/macosx/server

Apple MacOS X 10.2.2:

Apple Upgrade MacOS X 10.2.6

http://www.apple.com/macosx/” target=”_blank”>
http://www.apple.com/macosx/

Apple MacOS X Server 10.2.2:

Apple Upgrade MacOS X Server 10.2.6

http://www.apple.com/macosx/server” target=”_blank”>
http://www.apple.com/macosx/server

Apple MacOS X 10.2.3:

Apple Upgrade MacOS X 10.2.6

http://www.apple.com/macosx/” target=”_blank”>
http://www.apple.com/macosx/

Apple MacOS X Server 10.2.3:

Apple Upgrade MacOS X Server 10.2.6

http://www.apple.com/macosx/server” target=”_blank”>
http://www.apple.com/macosx/server

Apple MacOS X Server 10.2.4:

Apple Upgrade MacOS X Server 10.2.6

http://www.apple.com/macosx/server” target=”_blank”>
http://www.apple.com/macosx/server

Apple MacOS X 10.2.4:

Apple Upgrade MacOS X 10.2.6

http://www.apple.com/macosx/” target=”_blank”>
http://www.apple.com/macosx/

Apple MacOS X 10.2.5:

Apple Upgrade MacOS X 10.2.6

http://www.apple.com/macosx/” target=”_blank”>
http://www.apple.com/macosx/

Apple MacOS X Server 10.2.5:

Apple Upgrade MacOS X Server 10.2.6

http://www.apple.com/macosx/server” target=”_blank”>
http://www.apple.com/macosx/server

参考网址

来源:US-CERT Vulnerability Note: VU#869548
名称: VU#869548
链接:http://www.kb.cert.org/vuls/id/869548

来源: docs.info.apple.com
链接:http://docs.info.apple.com/article.html?artnum=61798

来源: XF
名称: macos-ipsec-acl-bypass(12027)
链接:http://xforce.iss.net/xforce/xfdb/12027

来源: BID
名称: 7628
链接:http://www.securityfocus.com/bid/7628

来源: SECTRACK
名称: 1006796
链接:http://securitytracker.com/id?1006796

来源: SECUNIA
名称: 8798
链接:http://secunia.com/advisories/8798

受影响实体

    暂无

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享