PT-2010-2258 · Apple · Macos X
Publicado
2010-03-30
·
Atualizado
2010-03-31
·
CVE-2010-0500
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Apple Mac OS X versions prior to 10.6.3
Description
The issue is related to a "plist injection issue" where the Event Monitor in Apple Mac OS X does not properly validate hostnames of SSH clients. This allows remote attackers to cause a denial of service by arbitrarily blacklisting clients via a crafted DNS PTR record.
Recommendations
For versions prior to 10.6.3, update to version 10.6.3 or later to resolve the issue. As a temporary workaround, consider restricting access to SSH services to minimize the risk of exploitation.
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Macos X