[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248149

 
 

909

 
 

194803

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

Information disclosure vulnerability in Apple Remote Desktop Client via cleartext VNC session - APPLE-SA-2013-10-22-7

ID: oval:org.secpod.oval:def:16097Date: (C)2013-11-26   (M)2022-10-10
Class: PATCHFamily: macos




The host is missing a security update according to Apple advisory, APPLE-SA-2013-10-22-7. The update is required to fix a information disclosure vulnerability. The flaws are present in the application, which does not properly use server authentication-type information during decisions about whether to present an unencrypted-connection warning message. Successful exploitation allows remote attackers to obtain sensitive information in opportunistic circumstances by sniffing the network during an unintended cleartext VNC session.

Platform:
Apple Mac OS X 10.8
Apple Mac OS X 10.9
Apple Mac OS X 10.10
Apple Mac OS X Server 10.8
Apple Mac OS X Server 10.9
Apple Mac OS X Server 10.10
Product:
Apple Remote Desktop Client
Reference:
APPLE-SA-2013-10-22-7
CVE-2013-5135
CVE-2013-5136
CVE    2
CVE-2013-5135
CVE-2013-5136
CPE    1
cpe:/a:apple:remote_desktop_client

© SecPod Technologies