Vulnerability Bulletins |
Ejecución remota de código en Java para Mac OS X |
|
Vulnerability classification |
|
| Property | Value |
| Confidence level | Oficial |
| Impact | Ejecucion remota de codigo |
| Dificulty | Experto |
| Required attacker level | Acceso remoto sin cuenta a un servicio estandar |
System information |
|
| Property | Value |
| Affected manufacturer | Comercial Software |
| Affected software |
Mac OS X v10.6.8 y Mac OS X Server v10.6.8. Mac OS X Lion v10.7.3 y Lion Server v10.7.3. |
Description |
|
|
Se ha descubierto una vulnerabilidad en Java para plataforma Mac OS X. La vulnerabilidad reside en la posible ejecución de código fuera del entorno sandbox. Un atacante remoto podría causar la ejecución remota de código mediante un applet malicioso. |
|
Solution |
|
|
Instalar la actualización 1.6.0_31. Se puede instalar de dos formas: - Desde el elemento del menú [Preferencias del sistema >> Actualización de Software]. - Desde la página de descarga de software de Apple. Http://support.apple.com/kb/HT1222 |
|
Standar resources |
|
| Property | Value |
| CVE |
CVE-2011-3563 CVE-2011-5035 CVE-2012-0497 CVE-2012-0498 CVE-2012-0499 CVE-2012-0500 CVE-2012-0501 CVE-2012-0502 CVE-2012-0503 CVE-2012-0505 CVE-2012-0506 CVE-2012-0507 |
| BID | |
Other resources |
|
|
About the security content of Java for OS X Lion 2012-001 and Java for Mac OS X 10.6 Update 7 https://support.apple.com/kb/HT5228 Java update for OS X patches Flashback malware exploit http://reviews.cnet.com/8301-13727_7-57408874-263/java-update-for-os-x-patches-flashback-malware-exploit/ |
|
Version history |
||
| Version | Comments | Date |
| 1.0 | Aviso emitido | 2012-04-06 |






