HTTP: Apple OS X Update Command Execution

This signature detects attempts to exploit a known vulnerability against Apple OS X software update. A successful attack can lead to arbitrary code execution.

Extended Description

Apple Mac OS X is prone to a weakness that may allow attackers to execute arbitrary commands. Successfully exploiting this issue in conjunction with other latent vulnerabilities may allow an attacker to execute arbitrary commands on affected computers, provided that the 'allow-external-scripts' option is enabled.

Affected Products

Apple mac_os_x

Short Name
HTTP:STC:OSX-UPDATE
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
Apple CVE-2007-5863 Command Execution OS Update X bid:26908
Release Date
12/19/2011
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3336
False Positive
Unknown
Vendors

Apple

CVSS Score

9.3

Found a potential security threat?