Mac OS X 10.8 < 10.8.5 Supplemental Update

medium Nessus Plugin ID 70301

Synopsis

The remote host is missing a Mac OS X security update that fixes a local security bypass vulnerability.

Description

The remote host is running a version of Mac OS X 10.8 that is missing the OS X v10.8.5 Supplemental Update. This update fixes a logic issue in verification of authentication credentials by Directory Services, which could otherwise allow a local attacker to bypass password validation.

Solution

Install the OS X v10.8.5 Supplemental Update.

See Also

http://support.apple.com/kb/HT5964

http://lists.apple.com/archives/security-announce/2013/Oct/msg00000.html

http://www.securityfocus.com/archive/1/528980/30/0/threaded

Plugin Details

Severity: Medium

ID: 70301

File Name: macosx_10_8_5_su1.nasl

Version: 1.7

Type: combined

Agent: macosx

Published: 10/4/2013

Updated: 11/27/2023

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.7

CVSS v2

Risk Factor: Medium

Base Score: 6.6

Temporal Score: 4.9

Vector: CVSS2#AV:L/AC:L/Au:N/C:N/I:C/A:C

Vulnerability Information

CPE: cpe:/o:apple:mac_os_x

Required KB Items: Host/local_checks_enabled, Host/MacOSX/Version

Exploit Ease: No known exploits are available

Patch Publication Date: 10/3/2013

Vulnerability Publication Date: 10/3/2013

Reference Information

CVE: CVE-2013-5163

BID: 62812

APPLE-SA: APPLE-SA-2013-10-03-1