PT-2013-5412 · Apple · Cfnetwork+2

Published

2013-10-24

·

Updated

2013-10-24

·

CVE-2013-5167

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions CFNetwork in Apple Mac OS X versions prior to 10.9
Description The issue concerns CFNetwork in Apple Mac OS X, where it does not properly handle the deletion of session cookies when a reset operation is performed in Safari. This makes it easier for remote web servers to track users through Set-Cookie HTTP headers.
Recommendations For versions prior to 10.9, update to version 10.9 or later to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-5167

Affected Products

Cfnetwork
Macos X
Safari