CVE-2010-4013: Medium severity apple ios and macos vulnerability
Published Jan 10, 2011
·Updated
Format string vulnerability in PackageKit in Apple Mac OS X 10.6.x before 10.6.6 allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to interaction between Software Update and distribution scripts.
Affected Software
12 affected components
Apple iOS and macOS=10.6.3
Apple iOS and macOS=10.6.1
Apple iOS and macOS=10.6.0
Apple iOS and macOS=10.6.2
Apple iOS and macOS=10.6.4
Apple iOS and macOS=10.6.5
Apple Mac OS X Server=10.6.3
Apple Mac OS X Server=10.6.4
Apple Mac OS X Server=10.6.5
Apple Mac OS X Server=10.6.1
Apple Mac OS X Server=10.6.2
Apple Mac OS X Server=10.6.0
Remediation
Patch Available
Event History
Jan 10, 2011
CVE Published
via MITRE·07:18 PM
Data Sourced
via MITRE·07:18 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2010-4013?
CVE-2010-4013 is rated as a high severity vulnerability that allows for remote code execution or denial of service.
2
How do I fix CVE-2010-4013?
To fix CVE-2010-4013, users should upgrade their Mac OS X to version 10.6.6 or later.
3
What versions of macOS are affected by CVE-2010-4013?
CVE-2010-4013 affects Apple Mac OS X versions 10.6.0 through 10.6.5.
4
Can CVE-2010-4013 be exploited remotely?
Yes, CVE-2010-4013 can be exploited remotely through man-in-the-middle attacks.
5
What type of vulnerability is CVE-2010-4013?
CVE-2010-4013 is a format string vulnerability related to PackageKit.