First published: Thu Oct 24 2013(Updated: )
Apple Keynote before 6.0 does not properly handle the interaction between Keynote presentation mode and the Screen Lock implementation, which allows physically proximate attackers to obtain access by visiting an unattended workstation on which this mode was enabled during a sleep operation.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Keynote | <=5.3 | |
Apple Keynote | =5.0 | |
Apple Keynote | =5.0.1 | |
Apple Keynote | =5.0.2 | |
Apple Keynote | =5.0.3 | |
Apple Keynote | =5.0.4 | |
Apple Keynote | =5.0.5 | |
Apple Keynote | =5.1 | |
Apple Keynote | =5.1.1 | |
Apple Keynote | =5.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-5148 has been classified as a medium severity vulnerability due to its potential for unauthorized access.
To fix CVE-2013-5148, update Apple Keynote to version 6.0 or later.
CVE-2013-5148 affects Apple Keynote versions prior to 6.0, including versions 5.0 to 5.3.
CVE-2013-5148 cannot be exploited remotely; the attacker must have physical access to the workstation.
The impact of CVE-2013-5148 allows unauthorized access to a user's session during Keynote presentation mode if the workstation is left unattended.