7.5
CVSSv2

CVE-2002-0676

Published: 11/07/2002 Updated: 05/09/2008
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SoftwareUpdate for MacOS 10.1.x does not use authentication when downloading a software update, which could allow remote malicious users to execute arbitrary code by posing as the Apple update server via techniques such as DNS spoofing or cache poisoning, and supplying Trojan Horse updates.

Vulnerable Product Search on Vulmon Subscribe to Product

apple mac os x 10.1.1

apple mac os x 10.1.2

apple mac os x 10.1.3

apple mac os x 10.1.4

apple mac os x 10.1

apple mac os x 10.1.5

Exploits

source: wwwsecurityfocuscom/bid/5176/info A vulnerability has been reported for MacOS X where an attacker may use SoftwareUpdate to install malicious software on the vulnerable system SoftwareUpdate uses HTTP, without any authentication, to obtain updates from Apple Any updated packages are installed on the system as the root user In ...