Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Alex Devries

#30428de 53,633
8.6CVSS total
Vulnerabilidades · 2
Média
2
PT-2008-2629
4.3
2008-06-02
Apple · Filing Protocol (Afp) Server · CVE-2008-1027
**Name of the Vulnerable Software and Affected Versions** Apple Mac OS X versions prior to 10.5.3 **Description** The issue concerns the Apple Filing Protocol (AFP) Server, which fails to verify that requested files and directories are within shared folders. This allows remote attackers to read arbitrary files via AFP traffic. **Recommendations** For versions prior to 10.5.3, update to version 10.5.3 or later to resolve the issue.
PT-2008-2614
4.3
2008-03-20
Apple · Apple Airport Extreme Base Station Firmware · CVE-2008-1012
**Name of the Vulnerable Software and Affected Versions** Apple AirPort Extreme Base Station Firmware version 7.3.1 **Description** The issue allows remote attackers to cause a denial of service, specifically a file sharing hang, by sending a crafted AFP request. This is related to input validation. **Recommendations** For Apple AirPort Extreme Base Station Firmware version 7.3.1, consider restricting access to the AFP service until a patch is available. As a temporary workaround, disabling the file sharing feature may help minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.