First published: Tue Dec 17 2013(Updated: )
Apple Safari 6.0.5 on Mac OS X 10.7.5 and 10.8.5 stores cleartext credentials in LastSession.plist, which allows local users to obtain sensitive information by reading this file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Safari | =6.0.5 | |
macOS Yosemite | =10.7.5 | |
macOS Yosemite | =10.8.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-7127 is classified as a medium severity vulnerability due to the exposure of cleartext credentials.
To resolve CVE-2013-7127, users should upgrade to a more secure version of Apple Safari that does not store credentials in cleartext.
If you are using Apple Safari version 6.0.5 on Mac OS X versions 10.7.5 or 10.8.5, your system is affected by CVE-2013-7127.
CVE-2013-7127 allows local users to access sensitive information, including cleartext credentials stored in the LastSession.plist file.
Currently, the best workaround for CVE-2013-7127 is to restrict local user access to the machine or to update the Safari browser to avoid using affected versions.