CVE-2016-4748

MEDIUM

Apple Mac OS X < 10.11.6 - Security Feature Bypass

Title source: rule

Description

Perl in Apple OS X before 10.12 allows local users to bypass the taint-mode protection mechanism via a crafted environment variable.

Scores

CVSS v3 5.3
EPSS 0.0006
EPSS Percentile 18.1%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Classification

CWE
CWE-254
Status published

Affected Products (2)

apple/mac_os_x < 10.11.6
n/a/n/a

Timeline

Published Sep 25, 2016
Tracked Since Feb 18, 2026