First published: Tue Nov 15 2011(Updated: )
The kSBXProfileNoNetwork and kSBXProfileNoInternet sandbox profiles in Apple Mac OS X 10.5.x through 10.7.x do not propagate restrictions to all created processes, which allows remote attackers to access network resources via a crafted application, as demonstrated by use of osascript to send Apple events to the launchd daemon, a related issue to CVE-2008-7303.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS and macOS | =10.5.0 | |
Apple iOS and macOS | =10.5.1 | |
Apple iOS and macOS | =10.5.2 | |
Apple iOS and macOS | =10.5.3 | |
Apple iOS and macOS | =10.5.4 | |
Apple iOS and macOS | =10.5.5 | |
Apple iOS and macOS | =10.5.6 | |
Apple iOS and macOS | =10.5.7 | |
Apple iOS and macOS | =10.5.8 | |
Apple iOS and macOS | =10.6.0 | |
Apple iOS and macOS | =10.6.1 | |
Apple iOS and macOS | =10.6.2 | |
Apple iOS and macOS | =10.6.3 | |
Apple iOS and macOS | =10.6.4 | |
Apple iOS and macOS | =10.6.5 | |
Apple iOS and macOS | =10.6.6 | |
Apple iOS and macOS | =10.6.7 | |
Apple iOS and macOS | =10.6.8 | |
Apple iOS and macOS | =10.7.0 | |
Apple iOS and macOS | =10.7.1 | |
Apple iOS and macOS | =10.7.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-1516 is classified as a high severity vulnerability due to its potential to allow remote attackers to access network resources.
To mitigate CVE-2011-1516, upgrade to a version of Mac OS X that has patched this vulnerability.
CVE-2011-1516 affects Mac OS X 10.5.x through 10.7.x.
CVE-2011-1516 can be exploited through crafted applications that bypass the intended network access restrictions.
Yes, CVE-2011-1516 specifically affects applications that utilize the sandbox profiles on the affected Mac OS X systems.