CVE-2013-0966

Apple mod_hfs_apple - Info Disclosure

Title source: llm
STIX 2.1

Description

The Apple mod_hfs_apple module for the Apache HTTP Server in Apple Mac OS X before 10.8.3 does not properly handle ignorable Unicode characters, which allows remote attackers to bypass intended directory authentication requirements via a crafted pathname in a URI.

References (1)

Core 1
Core References
Vendor Advisory vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2013/Mar/msg00002.html

Scores

EPSS 0.0170
EPSS Percentile 74.8%

Details

Status published
Products (17)
apple/mac_os_x 10.6.8
apple/mac_os_x 10.7.0
apple/mac_os_x 10.7.1
apple/mac_os_x 10.7.2
apple/mac_os_x 10.7.3
apple/mac_os_x 10.7.4
apple/mac_os_x 10.7.5
apple/mac_os_x 10.8.0
apple/mac_os_x 10.8.1
apple/mac_os_x 10.8.2
... and 7 more
Published Mar 15, 2013
Tracked Since Feb 18, 2026