Vulnerability Name: | CVE-2010-0502 (CCN-57271) | ||||||||
Assigned: | 2010-03-29 | ||||||||
Published: | 2010-03-29 | ||||||||
Updated: | 2010-03-31 | ||||||||
Summary: | iChat Server in Apple Mac OS X Server before 10.6.3, when group chat is used, does not perform logging for all types of messages, which might allow remote attackers to avoid message auditing via an unspecified selection of message type. Per: http://support.apple.com/kb/HT4077 'This issue only affects Mac OS X Server systems. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N) 3.2 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Bypass Security | ||||||||
References: | Source: MITRE Type: CNA CVE-2010-0502 Source: APPLE Type: Patch, Vendor Advisory APPLE-SA-2010-03-29-1 Source: CCN Type: SA39158 Apple Mac OS X Security Update Fixes Multiple Vulnerabilities Source: CCN Type: Apple Web site About the security content of Security Update 2010-002 / Mac OS X v10.6.3 Source: CONFIRM Type: Patch, Vendor Advisory http://support.apple.com/kb/HT4077 Source: CCN Type: OSVDB ID: 63408 Apple Mac OS X iChat Server Message Logging Failure Weakness Source: CCN Type: BID-39020 RETIRED: Apple Mac OS X APPLE-SA-2010-03-29-1 Multiple Security Vulnerabilities Source: XF Type: UNKNOWN macosx-ichatserver-groupchat-sec-bypass(57271) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |