HIGH · 7.5

CVE-2013-5135

Format string vulnerability in Screen Sharing Server in Apple Mac OS X before 10.9 and Apple Remote Desktop before 3.5.4 allows remote attackers to execute arbitrary code via format string specifiers ...

Vulnerability Description

Format string vulnerability in Screen Sharing Server in Apple Mac OS X before 10.9 and Apple Remote Desktop before 3.5.4 allows remote attackers to execute arbitrary code via format string specifiers in a VNC username.

CVSS Score

7.5

HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
AppleApple Remote Desktop<= 3.5.3
AppleMac Os X<= 10.8.5

Related Weaknesses (CWE)

References

FAQ

What is CVE-2013-5135?

CVE-2013-5135 is a vulnerability with a CVSS score of 7.5 (HIGH). Format string vulnerability in Screen Sharing Server in Apple Mac OS X before 10.9 and Apple Remote Desktop before 3.5.4 allows remote attackers to execute arbitrary code via format string specifiers ...

How severe is CVE-2013-5135?

CVE-2013-5135 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2013-5135?

Check the references section above for vendor advisories and patch information. Affected products include: Apple Apple Remote Desktop, Apple Mac Os X.