CVE-2003-1009
published 2004-03-29CVE-2003-1009: Directory Services in Apple Mac OS X 10.0.2, 10.0.3, 10.2.8, 10.3.2 and Apple Mac OS X Server 10.2 through 10.3.2 accepts authentication server information…
PriorityP336critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
4.57%
90.6th percentile
Directory Services in Apple Mac OS X 10.0.2, 10.0.3, 10.2.8, 10.3.2 and Apple Mac OS X Server 10.2 through 10.3.2 accepts authentication server information from unknown LDAP or NetInfo sources as provided by a malicious DHCP server, which allows remote attackers to gain privileges.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
http://docs.info.apple.com/article.html?artnum=32478http://docs.info.apple.com/article.html?artnum=61798http://www.carrel.org/dhcp-vuln.htmlhttp://www.securityfocus.com/bid/9110https://exchange.xforce.ibmcloud.com/vulnerabilities/13874http://docs.info.apple.com/article.html?artnum=32478http://docs.info.apple.com/article.html?artnum=61798http://www.carrel.org/dhcp-vuln.htmlhttp://www.securityfocus.com/bid/9110https://exchange.xforce.ibmcloud.com/vulnerabilities/13874
2004-03-29
Published