xfocus logo xfocus title
首页 焦点原创 安全文摘 安全工具 安全漏洞 焦点项目 焦点论坛 关于我们
English Version

Apple MacOS X IPSec基于端口的策略可绕过漏洞


发布时间:2003-05-19
更新时间:2003-05-19
严重程度:
威胁程度:欺骗
错误类型:设计错误
利用方式:服务器模式

BUGTRAQ ID:7628
CVE(CAN) ID:CAN-2003-0242

受影响系统
Apple MacOS X 10.0
Apple MacOS X 10.0.1
Apple MacOS X 10.0.2
Apple MacOS X 10.0.3
Apple MacOS X 10.0.4
Apple MacOS X 10.1
Apple MacOS X 10.1.1
Apple MacOS X 10.1.2
Apple MacOS X 10.1.3
Apple MacOS X 10.1.4
Apple MacOS X 10.1.5
Apple MacOS X 10.2
Apple MacOS X 10.2.1
Apple MacOS X 10.2.2
Apple MacOS X 10.2.3
Apple MacOS X 10.2.4
Apple MacOS X 10.2.5
Apple MacOS X Server 10.0
Apple MacOS X Server 10.2
Apple MacOS X Server 10.2.1
Apple MacOS X Server 10.2.2
Apple MacOS X Server 10.2.3
Apple MacOS X Server 10.2.4
Apple MacOS X Server 10.2.5
详细描述
MacOS X当使用IPSec功能时,由于不正确处理部分通信,基于端口的安全策略存在问题,这可导致未授权用户访问敏感服务。

测试代码
尚无

解决方案
升级程序:

Apple MacOS X Server 10.0:

Apple Upgrade MacOS X Server 10.2.6
http://www.apple.com/macosx/server

Apple MacOS X 10.0:

Apple Upgrade MacOS X 10.2.6
http://www.apple.com/macosx/

Apple MacOS X 10.0.1:

Apple Upgrade MacOS X 10.2.6
http://www.apple.com/macosx/

Apple MacOS X 10.0.2:

Apple Upgrade MacOS X 10.2.6
http://www.apple.com/macosx/

Apple MacOS X 10.0.3:

Apple Upgrade MacOS X 10.2.6
http://www.apple.com/macosx/

Apple MacOS X 10.0.4:

Apple Upgrade MacOS X 10.2.6
http://www.apple.com/macosx/

Apple MacOS X 10.1:

Apple Upgrade MacOS X 10.2.6
http://www.apple.com/macosx/

Apple MacOS X 10.1.1:

Apple Upgrade MacOS X 10.2.6
http://www.apple.com/macosx/

Apple MacOS X 10.1.2:

Apple Upgrade MacOS X 10.2.6
http://www.apple.com/macosx/

Apple MacOS X 10.1.3:

Apple Upgrade MacOS X 10.2.6
http://www.apple.com/macosx/

Apple MacOS X 10.1.4:

Apple Upgrade MacOS X 10.2.6
http://www.apple.com/macosx/

Apple MacOS X 10.1.5:

Apple Upgrade MacOS X 10.2.6
http://www.apple.com/macosx/

Apple MacOS X 10.2:

Apple Upgrade MacOS X 10.2.6
http://www.apple.com/macosx/

Apple MacOS X Server 10.2:

Apple Upgrade MacOS X Server 10.2.6
http://www.apple.com/macosx/server

Apple MacOS X 10.2.1:

Apple Upgrade MacOS X 10.2.6
http://www.apple.com/macosx/

Apple MacOS X Server 10.2.1:

Apple Upgrade MacOS X Server 10.2.6
http://www.apple.com/macosx/server

Apple MacOS X 10.2.2:

Apple Upgrade MacOS X 10.2.6
http://www.apple.com/macosx/

Apple MacOS X Server 10.2.2:

Apple Upgrade MacOS X Server 10.2.6
http://www.apple.com/macosx/server

Apple MacOS X 10.2.3:

Apple Upgrade MacOS X 10.2.6
http://www.apple.com/macosx/

Apple MacOS X Server 10.2.3:

Apple Upgrade MacOS X Server 10.2.6
http://www.apple.com/macosx/server

Apple MacOS X Server 10.2.4:

Apple Upgrade MacOS X Server 10.2.6
http://www.apple.com/macosx/server

Apple MacOS X 10.2.4:

Apple Upgrade MacOS X 10.2.6
http://www.apple.com/macosx/

Apple MacOS X 10.2.5:

Apple Upgrade MacOS X 10.2.6
http://www.apple.com/macosx/

Apple MacOS X Server 10.2.5:

Apple Upgrade MacOS X Server 10.2.6
http://www.apple.com/macosx/server

相关信息
参考:http://docs.info.apple.com/article.html?artnum=61798