CVE-2013-1027Apple MAC OS X vulnerability

CWE-2642 documents2 sources
Severity
6.8MEDIUMNVD
EPSS
0.5%
top 34.43%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 16
Latest updateMay 17

Description

Installer in Apple Mac OS X before 10.8.5 provides an option to continue a package's installation after encountering a revoked certificate, which might allow user-assisted remote attackers to execute arbitrary code via a crafted package.

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4

Affected Packages1 packages

NVDapple/mac_os_x10.8.4+4

Patches

🔴Vulnerability Details

1
GHSA
GHSA-5q95-vpjh-32v5: Installer in Apple Mac OS X before 102022-05-17