First published: Thu Oct 30 2003(Updated: )
Mac OS X before 10.3 initializes the TCP timestamp with a constant number, which allows remote attackers to determine the system's uptime via the ID field in a TCP packet.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
macOS Yosemite | <=10.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-0882 has been classified as a medium severity vulnerability due to the potential exposure of system uptime information.
To fix CVE-2003-0882, update your Mac OS X to version 10.3 or later to ensure secure TCP timestamp handling.
CVE-2003-0882 allows remote attackers to infer system uptime through analysis of the TCP timestamp ID field.
CVE-2003-0882 affects Mac OS X versions prior to 10.3.
Yes, CVE-2003-0882 can be exploited remotely by attackers observing TCP traffic to determine system uptime.