Time Machine in Apple Mac OS X before 10.7.3 does not verify the unique identifier of its remote AFP volume or Time Capsule, which allows remote attackers to obtain sensitive information contained in new backups by spoofing this storage object, a different vulnerability than CVE-2010-1803.
2012-02-02T18:55:01.520
2025-04-11T00:51:21.963
Deferred
CVSSv2: 5.0 (MEDIUM)
AV:N/AC:L/Au:N/C:P/I:N/A:N
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | apple | mac_os_x | ≤ 10.7.2 | Yes |
Operating System | apple | mac_os_x | 10.7.0 | Yes |
Operating System | apple | mac_os_x | 10.7.1 | Yes |
Operating System | apple | mac_os_x_server | ≤ 10.7.2 | Yes |
Operating System | apple | mac_os_x_server | 10.7.0 | Yes |
Operating System | apple | mac_os_x_server | 10.7.1 | Yes |