CVE-2010-0498: High severity Apple iOS and macOS vulnerability
Published Mar 30, 2010
·Updated
Directory Services in Apple Mac OS X before 10.6.3 does not properly perform authorization during processing of record names, which allows local users to gain privileges via unspecified vectors.
Affected Software
26 affected components
Apple iOS and macOS=10.5.8
Apple Mac OS X Server=10.5.2
Apple iOS and macOS=10.5.6
Apple Mac OS X Server=10.5.8
Apple iOS and macOS=10.5.5
Apple Mac OS X Server=10.5.5
Apple iOS and macOS=10.5.1
Apple Mac OS X Server=10.5.1
Apple Mac OS X Server=10.5.6
Apple iOS and macOS=10.5.3
Apple iOS and macOS=10.5.0
Apple Mac OS X Server=10.5.0
Apple Mac OS X Server=10.5.3
Apple iOS and macOS=10.5
Apple Mac OS X Server=10.5.4
Apple iOS and macOS=10.5.2
Apple Mac OS X Server=10.5.7
Apple Mac OS X Server=10.6.1
Apple iOS and macOS<=10.6.2
Apple iOS and macOS=10.6.1
Apple Mac OS X Server=10.6.0
Apple iOS and macOS=10.6.0
Apple iOS and macOS=10.5.7
Apple Mac OS X Server=10.5
Apple Mac OS X Server<=10.6.2
Apple iOS and macOS=10.5.4
Remediation
Patch Available
Event History
Mar 30, 2010
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Data Sourced
via NVD·06:30 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2010-0498?
CVE-2010-0498 is rated as a medium severity vulnerability due to its potential to allow local users to gain elevated privileges.
2
How do I fix CVE-2010-0498?
To fix CVE-2010-0498, update your Apple Mac OS X to version 10.6.3 or later.
3
Which versions of macOS are affected by CVE-2010-0498?
CVE-2010-0498 affects Apple Mac OS X versions prior to 10.6.3, including several 10.5.x versions.
4
Can CVE-2010-0498 be exploited remotely?
CVE-2010-0498 is a local privilege escalation vulnerability and cannot be exploited remotely.
5
What type of vulnerability is CVE-2010-0498?
CVE-2010-0498 is a directory services authorization vulnerability that allows local privilege escalation.