CVE-2013-5171: Low severity Apple iOS and macOS vulnerability
Published Oct 24, 2013
·Updated
CoreGraphics in Apple Mac OS X before 10.9 allows local users to bypass secure input mode and log an arbitrary application's keystrokes via a hotkey event registration.
Affected Software
7 affected components
Apple iOS and macOS<=10.8.5
Apple iOS and macOS=10.8.0
Apple iOS and macOS=10.8.1
Apple iOS and macOS=10.8.2
Apple iOS and macOS=10.8.3
Apple iOS and macOS=10.8.4
Apple iOS and macOS=10.8.5
Event History
Oct 24, 2013
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-5171?
CVE-2013-5171 is classified as a moderate severity vulnerability.
2
How do I fix CVE-2013-5171?
To fix CVE-2013-5171, update your Mac OS X to version 10.9 or later.
3
What does CVE-2013-5171 allow an attacker to do?
CVE-2013-5171 allows attackers to bypass secure input mode and log keystrokes from an arbitrary application.
4
Which versions of Mac OS X are affected by CVE-2013-5171?
CVE-2013-5171 affects Mac OS X versions prior to 10.9, including versions 10.8.0 to 10.8.5.
5
Who can exploit CVE-2013-5171?
CVE-2013-5171 can be exploited by local users with access to the affected systems.