Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:32569
HistoryOct 25, 2015 - 12:00 a.m.

APPLE-SA-2015-10-21-8 OS X Server 5.0.15

2015-10-2500:00:00
vulners.com
55

APPLE-SA-2015-10-21-8 OS X Server 5.0.15

OS X Server 5.0.15 is now available and addresses the following:

BIND
Available for: OS X Yosemite 10.10.5,
OS X El Capitan 10.11.1 or later
Impact: Multiple vulnerabilities in BIND
Description: Multiple vulnerabilities existed in BIND versions prior
to 9.9.7-P3, one of which may have allowed a remote attacker to cause
a denial of service. These issues were addressed by updating BIND to
version 9.9.7-P3.
CVE-ID
CVE-2015-5722 : Hanno Bock from the Fuzzing Project
CVE-2015-5986

Web Service
Available for: OS X Yosemite 10.10.5,
OS X El Capitan 10.11.1 or later
Impact: A remote attacker may be able to bypass access restrictions
Description: An HTTP header field reference was missing from the
configuration files. This issue was addressed by adding the HTTP
header field reference to the configuration file.
CVE-ID
CVE-2015-7031 : an anonymous researcher

Installation note:

OS X Server 5.0.15 may be obtained from the Mac App Store.

Information will also be posted to the Apple Security Updates
web site: https://support.apple.com/kb/HT201222

This message is signed with Apple's Product Security PGP key,
and details are available at:
https://www.apple.com/support/security/pgp/