First published: Thu Jul 11 2002(Updated: )
SoftwareUpdate for MacOS 10.1.x does not use authentication when downloading a software update, which could allow remote attackers to execute arbitrary code by posing as the Apple update server via techniques such as DNS spoofing or cache poisoning, and supplying Trojan Horse updates.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Mac OS X | =10.1 | |
Apple Mac OS X | =10.1.4 | |
Apple Mac OS X | =10.1.3 | |
Apple Mac OS X | =10.1.5 | |
Apple Mac OS X | =10.1.1 | |
Apple Mac OS X | =10.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.