CVE-2016-1773Apple MAC OS X vulnerability

CWE-2647 documents4 sources
Severity
3.3LOWNVD
EPSS
0.1%
top 83.03%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 24
Latest updateMay 17

Description

The code-signing subsystem in Apple OS X before 10.11.4 does not properly verify file ownership, which allows local users to determine the existence of arbitrary files via unspecified vectors.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 1.8 | Impact: 1.4

🔴Vulnerability Details

1
GHSA
GHSA-2987-5c42-f4x4: The code-signing subsystem in Apple OS X before 102022-05-17

📋Vendor Advisories

1
Apple
CVE-2016-1773: OS X El Capitan v10.11.4 and Security Update 2016-002

💬Community

4
Bugzilla
CVE-2016-0791 jenkins: Non-constant time comparison of CSRF crumbs (SECURITY-245)2016-02-25
Bugzilla
CVE-2016-0788 jenkins: Remote code execution vulnerability in remoting module (SECURITY-232)2016-02-25
Bugzilla
CVE-2016-0789 jenkins: HTTP response splitting vulnerability (SECURITY-238)2016-02-25
Bugzilla
CVE-2016-0790 jenkins: Non-constant time comparison of API token (SECURITY-241)2016-02-25