首页 -> 安全研究

安全研究

安全漏洞
MacOS X IPSec端口安全策略可绕过漏洞

发布日期:2003-05-19
更新日期:2003-05-26

受影响系统:
Apple MacOS X Server 10.2.5
Apple MacOS X Server 10.2.4
Apple MacOS X Server 10.2.3
Apple MacOS X Server 10.2.2
Apple MacOS X Server 10.2
Apple MacOS X Server 10.0
Apple MacOS X 10.2.5
Apple MacOS X 10.2.4
Apple MacOS X 10.2.3
Apple MacOS X 10.2.2
Apple MacOS X 10.2.1
Apple MacOS X 10.2 (Jaguar)
Apple MacOS X 10.1.5
Apple MacOS X 10.1.4
Apple MacOS X 10.1.3
Apple MacOS X 10.1.2
Apple MacOS X 10.1.1
Apple MacOS X 10.1
Apple MacOS X 10.0.4
Apple MacOS X 10.0.3
Apple MacOS X 10.0.2
Apple MacOS X 10.0.1
Apple MacOS X 10.0
不受影响系统:
Apple MacOS X Server 10.2.6
Apple MacOS X 10.2.6
描述:
BUGTRAQ  ID: 7628
CVE(CAN) ID: CVE-2003-0242

Mac OS X是一款使用在Mac机器上的操作系统,基于BSD系统。

MacOS X在使能IPSec时不正确处理部分通信,远程攻击者可以利用这个漏洞未授权访问部分敏感服务。

问题是Mac OS X 10.2.6版本在使用IPSec时,那些由端口进行匹配的安全策略不正确处理部分通信,可导致攻击者绕过安全限制访问部分敏感服务。

<*来源:Apple Security Updates
  
  链接:http://docs.info.apple.com/article.html?artnum=61798
*>

建议:
厂商补丁:

Apple
-----
目前厂商已经发布了升级补丁以修复这个安全问题,请到厂商的主页下载:

Apple MacOS X Server 10.0:

Apple Upgrade MacOS X Server 10.2.6
http://www.apple.com/macosx/server

Apple MacOS X 10.0:

Apple Upgrade MacOS X 10.2.6
http://www.apple.com/macosx/

Apple MacOS X 10.0.1:

Apple Upgrade MacOS X 10.2.6
http://www.apple.com/macosx/

Apple MacOS X 10.0.2:

Apple Upgrade MacOS X 10.2.6
http://www.apple.com/macosx/

Apple MacOS X 10.0.3:

Apple Upgrade MacOS X 10.2.6
http://www.apple.com/macosx/

Apple MacOS X 10.0.4:

Apple Upgrade MacOS X 10.2.6
http://www.apple.com/macosx/

Apple MacOS X 10.1:

Apple Upgrade MacOS X 10.2.6
http://www.apple.com/macosx/

Apple MacOS X 10.1.1:

Apple Upgrade MacOS X 10.2.6
http://www.apple.com/macosx/

Apple MacOS X 10.1.2:

Apple Upgrade MacOS X 10.2.6
http://www.apple.com/macosx/

Apple MacOS X 10.1.3:

Apple Upgrade MacOS X 10.2.6
http://www.apple.com/macosx/

Apple MacOS X 10.1.4:

Apple Upgrade MacOS X 10.2.6
http://www.apple.com/macosx/

Apple MacOS X 10.1.5:

Apple Upgrade MacOS X 10.2.6
http://www.apple.com/macosx/

Apple MacOS X 10.2:

Apple Upgrade MacOS X 10.2.6
http://www.apple.com/macosx/

Apple MacOS X Server 10.2:

Apple Upgrade MacOS X Server 10.2.6
http://www.apple.com/macosx/server

Apple MacOS X 10.2.1:

Apple Upgrade MacOS X 10.2.6
http://www.apple.com/macosx/

Apple MacOS X Server 10.2.1:

Apple Upgrade MacOS X Server 10.2.6
http://www.apple.com/macosx/server

Apple MacOS X 10.2.2:

Apple Upgrade MacOS X 10.2.6
http://www.apple.com/macosx/

Apple MacOS X Server 10.2.2:

Apple Upgrade MacOS X Server 10.2.6
http://www.apple.com/macosx/server

Apple MacOS X 10.2.3:

Apple Upgrade MacOS X 10.2.6
http://www.apple.com/macosx/

Apple MacOS X Server 10.2.3:

Apple Upgrade MacOS X Server 10.2.6
http://www.apple.com/macosx/server

Apple MacOS X Server 10.2.4:

Apple Upgrade MacOS X Server 10.2.6
http://www.apple.com/macosx/server

Apple MacOS X 10.2.4:

Apple Upgrade MacOS X 10.2.6
http://www.apple.com/macosx/

Apple MacOS X 10.2.5:

Apple Upgrade MacOS X 10.2.6
http://www.apple.com/macosx/

Apple MacOS X Server 10.2.5:

Apple Upgrade MacOS X Server 10.2.6
http://www.apple.com/macosx/server

浏览次数:2821
严重程度:0(网友投票)
本安全漏洞由绿盟科技翻译整理,版权所有,未经许可,不得转载
绿盟科技给您安全的保障