[Forgot Password]
Login  Register Subscribe

30389

 
 

423868

 
 

244625

 
 

909

 
 

193379

 
 

277

Paid content will be excluded from the download.


Download | Alert*
OVAL

Information disclosure vulnerability in iBooks via XML External Entity (Mac OS X) - APPLE-SA-2016-03-31-1

ID: oval:org.secpod.oval:def:48179Date: (C)2018-10-24   (M)2022-10-10
Class: PATCHFamily: macos




The host is missing a security update according to apple advisory, APPLE-SA-2016-03-31-1. The update is required to fix an information disclosure vulnerability. A flaw is present in the application, which fails to handle the issue in XML External Entity (XXE). Successful exploitation allows remote attackers to read arbitrary files via an iBooks Author file.

Platform:
Apple Mac OS X 10.10
Apple Mac OS X 10.11
Apple Mac OS X 10.12
Apple Mac OS X 10.13
Apple Mac OS X 10.14
Product:
iBooks
Reference:
APPLE-SA-2016-03-31-1
CVE-2016-1789
CVE    1
CVE-2016-1789
CPE    2
cpe:/a:apple:ibooks_author
cpe:/a:apple:ibooks_author:2.4.0

© SecPod Technologies