CVE-2013-5183: Infoleak
Published Oct 24, 2013
·Updated
Mail in Apple Mac OS X before 10.9, when Kerberos authentication is enabled and TLS is disabled, sends invalid cleartext data, which allows remote attackers to obtain sensitive information by sniffing the network.
Affected Software
7 affected components
Apple iOS and macOS<=10.8.5
Apple iOS and macOS=10.8.0
Apple iOS and macOS=10.8.1
Apple iOS and macOS=10.8.2
Apple iOS and macOS=10.8.3
Apple iOS and macOS=10.8.4
Apple iOS and macOS=10.8.5
Event History
Oct 24, 2013
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-5183?
CVE-2013-5183 is considered a medium severity vulnerability due to potential exposure of sensitive information.
2
How do I fix CVE-2013-5183?
To mitigate CVE-2013-5183, ensure that Kerberos authentication is enabled and TLS is enabled in Apple Mail settings.
3
What versions of Mac OS X are affected by CVE-2013-5183?
CVE-2013-5183 affects Apple Mac OS X versions prior to 10.9, including versions up to 10.8.5.
4
What type of data is exposed by CVE-2013-5183?
CVE-2013-5183 may expose cleartext data, which can include sensitive information sent over the network.
5
Can CVE-2013-5183 be exploited remotely?
Yes, CVE-2013-5183 can be exploited remotely by attackers sniffing the network traffic.