PT-2002-1702 · Apple · Apple Macos+1
Publicado
2002-07-11
·
Atualizado
2008-09-05
·
CVE-2002-0676
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
SoftwareUpdate for MacOS versions 10.1.x
Description
The issue allows remote attackers to execute arbitrary code by posing as the Apple update server via techniques such as DNS spoofing or cache poisoning, and supplying Trojan Horse updates, because the software update does not use authentication when downloading updates.
Recommendations
For MacOS versions 10.1.x, consider disabling the automatic software update feature until a patch is available, and instead manually download updates from trusted sources to minimize the risk of exploitation.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Apple Macos
Hp Software Update