CVE Database
/

CVE-2002-0676

Back to search

CVE-2002-0676

Published: Apr 2, 2003

Modified: Aug 8, 2024

PUBLISHED

Description

SoftwareUpdate for MacOS 10.1.x does not use authentication when downloading a software update, which could allow remote attackers to execute arbitrary code by posing as the Apple update server via techniques such as DNS spoofing or cache poisoning, and supplying Trojan Horse updates.

VendorProductVersions

n/a

n/a

affected
n/a

References

5137
vdb-entry
x_refsource_OSVDB
5176
vdb-entry
x_refsource_BID
macos-softwareupdate-no-auth(9502)
vdb-entry
x_refsource_XF

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now