Vulnerabilities > CVE-2013-0973 - Unspecified vulnerability in Apple mac OS X and mac OS X Server
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN apple
nessus
Summary
Software Update in Apple Mac OS X through 10.7.5 does not prevent plugin loading within the marketing-text WebView, which allows man-in-the-middle attackers to execute plugin code by modifying the client-server data stream.
Vulnerable Configurations
Nessus
NASL family | MacOS X Local Security Checks |
NASL id | MACOSX_SECUPD2013-001.NASL |
description | The remote host is running a version of Mac OS X 10.6 or 10.7 that does not have Security Update 2013-001 applied. This update contains numerous security-related fixes for the following components : - Apache - CoreTypes (10.7 only) - International Components for Unicode - Identity Services (10.7 only) - ImageIO - Messages Server (Server only) - PDFKit - Podcast Producer Server (Server only) - PostgreSQL (Server only) - Profile Manager (10.7 Server only) - QuickTime - Ruby (10.6 Server only) - Security - Software Update - Wiki Server (10.7 Server only) Note that the update also runs a malware removal tool that will remove the most common variants of malware. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 65578 |
published | 2013-03-15 |
reporter | This script is Copyright (C) 2013-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/65578 |
title | Mac OS X Multiple Vulnerabilities (Security Update 2013-001) |
code |
|
Seebug
bulletinFamily exploit description BUGTRAQ ID: 58514 CVE(CAN) ID: CVE-2013-0973 Apple Mac OS X是苹果电脑操作系统软件。 Apple Mac OS X 10.8.3之前版本的软件更新没有阻止marketing-text WebView内的插件加载,允许中间人攻击者通过修改客户端到服务器数据流,执行插件代码。 0 Apple Mac OS X 10.7.4 Apple Mac OS X 10.7.3 Apple Mac OS X 10.7.2 Apple Mac OS X 10.7.1 Apple Mac OS X Server 10.7.4 Apple Mac OS X Server 10.7.3 Apple Mac OS X Server 10.7.2 Apple Mac OS X Server 10.7.1 Apple Mac OS X Server 10.7 Apple Mac OS X Server 10.6.8 厂商补丁: Apple ----- 目前厂商已经发布了升级补丁以修复这个安全问题,请到厂商的主页下载: http://support.apple.com/ id SSV:60686 last seen 2017-11-19 modified 2013-03-19 published 2013-03-19 reporter Root title Apple Mac OS X 远程代码执行漏洞 bulletinFamily exploit description BUGTRAQ ID: 58494 CVE(CAN) ID: CVE-2013-0966,CVE-2013-0967,CVE-2013-0969,CVE-2013-0970,CVE-2013-0971,CVE-2013-0973,CVE-2013-0976 Apple Mac OS X是苹果电脑操作系统软件。 Apple Mac OS X 10.8.3之前版本在实现上存在多个安全漏洞,攻击者可利用这些漏洞执行任意代码、造成拒绝服务、未授权访问、窃取敏感信息、绕过安全限制及其他攻击。 0 Apple Mac OS X 10.7.4 Apple Mac OS X 10.7.3 Apple Mac OS X 10.7.2 Apple Mac OS X 10.7.1 Apple Mac OS X Server 10.7.4 Apple Mac OS X Server 10.7.3 Apple Mac OS X Server 10.7.2 Apple Mac OS X Server 10.7.1 Apple Mac OS X Server 10.7 Apple Mac OS X Server 10.6.8 厂商补丁: Apple ----- 目前厂商已经发布了升级补丁以修复这个安全问题,请到厂商的主页下载: http://support.apple.com/ id SSV:60678 last seen 2017-11-19 modified 2013-03-19 published 2013-03-19 reporter Root title Apple Mac OS X 多个安全漏洞(2013-001)