CVE-2009-0013: Low severity Apple iOS and macOS vulnerability
Published Feb 13, 2009
·Updated
dscl in DS Tools in Apple Mac OS X 10.4.11 and 10.5.6 requires that passwords must be provided as command line arguments, which allows local users to gain privileges by listing process information.
Affected Software
4 affected components
Apple iOS and macOS=10.5.6
Apple Mac OS X Server=10.4.11
Apple Mac OS X Server=10.5.6
Apple iOS and macOS=10.4.11
Remediation
Event History
Feb 13, 2009
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·12:30 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2009-0013?
CVE-2009-0013 is classified as a local privilege escalation vulnerability.
2
How do I fix CVE-2009-0013?
To fix CVE-2009-0013, update to the latest version of Mac OS X that addresses this issue.
3
Who is affected by CVE-2009-0013?
CVE-2009-0013 affects users of Mac OS X 10.4.11 and 10.5.6, including both the standard and server editions.
4
Can CVE-2009-0013 be exploited remotely?
CVE-2009-0013 cannot be exploited remotely as it requires local access to the system.
5
What are the consequences of CVE-2009-0013?
The consequences of CVE-2009-0013 include unauthorized privilege escalation for local users.