PT-2002-1702 · Apple · Apple Macos+1

Publicado

2002-07-11

·

Atualizado

2008-09-05

·

CVE-2002-0676

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions SoftwareUpdate for MacOS versions 10.1.x
Description The issue allows remote attackers to execute arbitrary code by posing as the Apple update server via techniques such as DNS spoofing or cache poisoning, and supplying Trojan Horse updates, because the software update does not use authentication when downloading updates.
Recommendations For MacOS versions 10.1.x, consider disabling the automatic software update feature until a patch is available, and instead manually download updates from trusted sources to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2002-0676

Produtos afetados

Apple Macos
Hp Software Update