OS X Server 5.0.15 is now available and addresses the following:
BIND
Available for: OS X Yosemite 10.10.5,
OS X El Capitan 10.11.1 or later
Impact: Multiple vulnerabilities in BIND
Description: Multiple vulnerabilities existed in BIND versions prior
to 9.9.7-P3, one of which may have allowed a remote attacker to cause
a denial of service. These issues were addressed by updating BIND to
version 9.9.7-P3.
CVE-ID
CVE-2015-5722 : Hanno Böck from the Fuzzing Project
CVE-2015-5986
Web Service
Available for: OS X Yosemite 10.10.5,
OS X El Capitan 10.11.1 or later
Impact: A remote attacker may be able to bypass access restrictions
Description: An HTTP header field reference was missing from the
configuration files. This issue was addressed by adding the HTTP
header field reference to the configuration file.
CVE-ID
CVE-2015-7031 : an anonymous researcher
Installation note:
OS X Server 5.0.15 may be obtained from the Mac App Store.
Information will also be posted to the Apple Security Updates
web site: https://support.apple.com/kb/
This message is signed with Apple's Product Security PGP key,
and details are available at:
https://www.apple.com/support/
Komentarų nėra:
Rašyti komentarą