PT-2002-1702 · Apple · Apple Macos+1

Published

2002-07-11

·

Updated

2008-09-05

·

CVE-2002-0676

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions SoftwareUpdate for MacOS versions 10.1.x
Description The issue allows remote attackers to execute arbitrary code by posing as the Apple update server via techniques such as DNS spoofing or cache poisoning, and supplying Trojan Horse updates, because the software update does not use authentication when downloading updates.
Recommendations For MacOS versions 10.1.x, consider disabling the automatic software update feature until a patch is available, and instead manually download updates from trusted sources to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-0676

Affected Products

Apple Macos
Hp Software Update