===================================================================== CERT-Renater Note d'Information No. 2013/VULN038 _____________________________________________________________________ DATE : 06/02/2013 HARDWARE PLATFORM(S): / OPERATING SYSTEM(S) : OS X Server versions prior to 2.2.1. ====================================================================== http://support.apple.com/kb/HT5644 ______________________________________________________________________ APPLE-SA-2013-02-04-1 OS X Server v2.2.1 OS X Server v2.2.1 is now available and addresses the following: Profile Manager Available for: OS X Mountain Lion v10.8 or later Impact: A remote attacker may be able to cause arbitrary code execution Description: A type casting issue existed in Ruby on Rails' handling of XML parameters. This issue was addressed by disabling XML parameters in the Rails implementation used by Profile Manager. CVE-ID CVE-2013-0156 Wiki Server Available for: OS X Mountain Lion v10.8 or later Impact: A remote attacker may be able to cause arbitrary code execution Description: A type casting issue existed in Ruby on Rails' handling of XML parameters. This issue was addressed by disabling XML parameters in the Rails implementation used by Wiki Server. CVE-ID CVE-2013-0156 Wiki Server Available for: OS X Mountain Lion v10.8 or later Impact: A remote attacker may be able to cause arbitrary code execution Description: A type casting issue existed in Ruby on Rails' handling of JSON data. This issue was addressed by switching to using the JSONGem backend for JSON parsing. CVE-ID CVE-2013-0333 OS X Server v2.2.1 may be obtained from Mac App Store. Information will also be posted to the Apple Security Updates web site: http://support.apple.com/kb/HT1222 This message is signed with Apple's Product Security PGP key, and details are available at: https://www.apple.com/support/security/pgp/ ====================================================================== ========================================================= Serveur de référence du CERT-Renater https://services.renater.fr/ssi/ ========================================================= + CERT-RENATER | tel : 01-53-94-20-44 + + 23 - 25 Rue Daviel | fax : 01-53-94-20-41 + + 75013 Paris | email: certsvp@renater.fr + =========================================================