Описание
Apple Mac OS X does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning.
Ссылки
- Broken Link
- Broken Link
- Broken Link
- Broken Link
- Broken Link
- Broken Link
Уязвимые конфигурации
Конфигурация 1Версия от 10.0.0 (включая) до 10.5.4 (включая)
cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*
EPSS
Процентиль: 62%
0.0043
Низкий
8.1 High
CVSS3
7.5 High
CVSS2
Дефекты
CWE-494
Связанные уязвимости
CVSS3: 8.1
github
почти 4 года назад
Apple Mac OS X does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning.
EPSS
Процентиль: 62%
0.0043
Низкий
8.1 High
CVSS3
7.5 High
CVSS2
Дефекты
CWE-494