Vulnerabilities > CVE-2002-0676 - Unspecified vulnerability in Apple mac OS X

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
apple
exploit available

Summary

SoftwareUpdate for MacOS 10.1.x does not use authentication when downloading a software update, which could allow remote attackers to execute arbitrary code by posing as the Apple update server via techniques such as DNS spoofing or cache poisoning, and supplying Trojan Horse updates.

Exploit-Db

descriptionMacOS X 10.1.x SoftwareUpdate Arbitrary Package Installation Vulnerability. CVE-2002-0676. Remote exploit for osx platform
idEDB-ID:21596
last seen2016-02-02
modified2002-07-08
published2002-07-08
reporterRussell Harding
sourcehttps://www.exploit-db.com/download/21596/
titleMacOS X 10.1.x SoftwareUpdate Arbitrary Package Installation Vulnerability