CVE-2013-1030: Infoleak
Published Sep 16, 2013
·Updated
mdmclient in Mobile Device Management in Apple Mac OS X before 10.8.5 places a password on the command line, which allows local users to obtain sensitive information by listing the process.
Affected Software
5 affected components
Apple iOS and macOS<=10.8.4
Apple iOS and macOS=10.8.0
Apple iOS and macOS=10.8.1
Apple iOS and macOS=10.8.2
Apple iOS and macOS=10.8.3
Remediation
Patch Available
Event History
Sep 16, 2013
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-1030?
CVE-2013-1030 is classified as a high-severity vulnerability due to its potential for local information exposure.
2
How do I fix CVE-2013-1030?
To fix CVE-2013-1030, update to Apple Mac OS X version 10.8.5 or later.
3
What type of vulnerability is CVE-2013-1030?
CVE-2013-1030 is a local information disclosure vulnerability.
4
Who is affected by CVE-2013-1030?
CVE-2013-1030 affects users of Apple Mac OS X versions earlier than 10.8.5.
5
What does CVE-2013-1030 exploit?
CVE-2013-1030 exploits the mdmclient process, which incorrectly handles password visibility in process listings.