ID

VAR-201303-0127


CVE

CVE-2013-0971


TITLE

Apple Mac OS X of PDFKit Vulnerable to arbitrary code execution

Trust: 0.8

sources: JVNDB: JVNDB-2013-001852

DESCRIPTION

Use-after-free vulnerability in PDFKit in Apple Mac OS X before 10.8.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted ink annotations in a PDF document. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.The specific flaw exists within the parsing of a PDF file. During the processing of a specific InkList array, a reference is created to an object that is freed before use. By abusing this behavior an attacker can ensure this memory is under control and leverage the situation to achieve remote code execution under the context of the user currently logged in. Apple Mac OS X is prone to multiple vulnerabilities. The update addresses new vulnerabilities that affect Apache, CoreTypes, IOAcceleratorFamily, Login Window, Messages, PDFKit, and Software Update. Attackers can exploit these issues to execute arbitrary code, cause denial-of-service conditions, gain unauthorized access, obtain sensitive information, bypass security restrictions, and perform other attacks. These issues affect OS X prior to 10.8.3. Note: This issue was previously discussed in BID 58494 (Apple Mac OS X Security Update 2013-001 Multiple Security Vulnerabilities), but has been given its own record to better document it. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 APPLE-SA-2013-03-14-1 OS X Mountain Lion v10.8.3 and Security Update 2013-001 OS X Mountain Lion v10.8.3 and Security Update 2013-001 is now available and addresses the following: Apache Available for: Mac OS X 10.6.8, Mac OS X Server 10.6.8, OS X Lion v10.7 to v10.7.5, OS X Lion Server v10.7 to v10.7.5, OS X Mountain Lion v10.8 to v10.8.2 Impact: An attacker may be able to access directories that are protected with HTTP authentication without knowing the correct credentials Description: A canonicalization issue existed in the handling of URIs with ignorable Unicode character sequences. This issue was addressed by updating mod_hfs_apple to forbid access to URIs with ignorable Unicode character sequences. CVE-ID CVE-2013-0966 : Clint Ruoho of Laconic Security CoreTypes Available for: OS X Lion v10.7 to v10.7.5, OS X Lion Server v10.7 to v10.7.5, OS X Mountain Lion v10.8 to v10.8.2 Impact: Visiting a maliciously crafted website could allow a Java Web Start application to be launched automatically even if the Java plug-in is disabled Description: Java Web Start applications would run even if the Java plug-in was disabled. This issue was addressed by removing JNLP files from the CoreTypes safe file type list, so the Web Start application will not be run unless the user opens it in the Downloads directory. CVE-ID CVE-2013-0967 International Components for Unicode Available for: Mac OS X 10.6.8, Mac OS X Server 10.6.8, OS X Lion v10.7 to v10.7.5, OS X Lion Server v10.7 to v10.7.5, OS X Mountain Lion v10.8 to v10.8.2 Impact: Visiting a maliciously crafted website may lead to a cross- site scripting attack Description: A canonicalization issue existed in the handling of the EUC-JP encoding, which could lead to a cross-site scripting attack on EUC-JP encoded websites. This issue was addressed by updating the EUC-JP mapping table. CVE-ID CVE-2011-3058 : Masato Kinugawa Identity Services Available for: OS X Lion v10.7 to v10.7.5, OS X Lion Server v10.7 to v10.7.5, OS X Mountain Lion v10.8 to v10.8.2 Impact: Authentication relying on certificate-based Apple ID authentication may be bypassed Description: An error handling issue existed in Identity Services. If the user's AppleID certificate failed to validate, the user's AppleID was assumed to be the empty string. If multiple systems belonging to different users enter this state, applications relying on this identity determination may erroneously extend trust. This issue was addressed by ensuring that NULL is returned instead of an empty string. CVE-ID CVE-2013-0963 ImageIO Available for: Mac OS X 10.6.8, Mac OS X Server 10.6.8, OS X Lion v10.7 to v10.7.5, OS X Lion Server v10.7 to v10.7.5, OS X Mountain Lion v10.8 to v10.8.2 Impact: Viewing a maliciously crafted TIFF file may lead to an unexpected application termination or arbitrary code execution Description: A buffer overflow existed in libtiff's handling of TIFF images. This issue was addressed through additional validation of TIFF images. CVE-ID CVE-2012-2088 IOAcceleratorFamily Available for: OS X Mountain Lion v10.8 to v10.8.2 Impact: Viewing a maliciously crafted image may lead to an unexpected system termination or arbitrary code execution Description: A memory corruption issue existed in the handling of graphics data. This issue was addressed through improved bounds checking. CVE-ID CVE-2013-0976 : an anonymous researcher Kernel Available for: OS X Mountain Lion v10.8 to v10.8.2 Impact: Maliciously crafted or compromised applications may be able to determine addresses in the kernel Description: An information disclosure issue existed in the handling of APIs related to kernel extensions. Responses containing an OSBundleMachOHeaders key may have included kernel addresses, which may aid in bypassing address space layout randomization protection. This issue was addressed by unsliding the addresses before returning them. CVE-ID CVE-2012-3749 : Mark Dowd of Azimuth Security, Eric Monti of Square, and additional anonymous researchers Login Window Available for: OS X Mountain Lion v10.8 to v10.8.2 Impact: An attacker with keyboard access may modify the system configuration Description: A logic error existed in VoiceOver's handling of the Login Window, whereby an attacker with access to the keyboard could launch System Preferences and modify the system configuration. This issue was addressed by preventing VoiceOver from launching applications at the Login Window. CVE-ID CVE-2013-0969 : Eric A. Schulman of Purpletree Labs Messages Available for: OS X Mountain Lion v10.8 to v10.8.2 Impact: Clicking a link from Messages may initiate a FaceTime call without prompting Description: Clicking on a specifically-formatted FaceTime:// URL in Messages could bypass the standard confirmation prompt. This issue was addressed by additional validation of FaceTime:// URLs. CVE-ID CVE-2013-0970 : Aaron Sigel of vtty.com Messages Server Available for: Mac OS X Server 10.6.8, OS X Lion Server v10.7 to v10.7.5 Impact: A remote attacker may reroute federated Jabber messages Description: An issue existed in the Jabber server's handling of dialback result messages. An attacker may cause the Jabber server to disclose information intended for users of federated servers. This issue was addressed through improved handling of dialback result messages. This issue was addressed through improved memory management. CVE-ID CVE-2013-0971 : Tobias Klein working with HP TippingPoint's Zero Day Initiative Podcast Producer Server Available for: Mac OS X Server 10.6.8, OS X Lion Server v10.7 to v10.7.5 Impact: A remote attacker may be able to cause arbitrary code execution Description: A type casting issue existed in Ruby on Rails' handling of XML parameters. This issue was addressed by disabling XML parameters in the Rails implementation used by Podcast Producer Server. CVE-ID CVE-2013-0156 Podcast Producer Server Available for: OS X Lion Server v10.7 to v10.7.5 Impact: A remote attacker may be able to cause arbitrary code execution Description: A type casting issue existed in Ruby on Rails' handling of JSON data. This issue was addressed by switching to using the JSONGem backend for JSON parsing in the Rails implementation used by Podcast Producer Server. CVE-ID CVE-2013-0333 PostgreSQL Available for: Mac OS X Server 10.6.8, OS X Lion Server v10.7 to v10.7.5 Impact: Multiple vulnerabilities in PostgreSQL Description: PostgreSQL was updated to version 9.1.5 to address multiple vulnerabilities, the most serious of which may allow database users to read files from the file system with the privileges of the database server role account. Further information is available via the PostgreSQL web site at http://www.postgresql.org/docs/9.1/static/release-9-1-5.html CVE-ID CVE-2012-3488 CVE-2012-3489 Profile Manager Available for: OS X Lion Server v10.7 to v10.7.5 Impact: A remote attacker may be able to cause arbitrary code execution Description: A type casting issue existed in Ruby on Rails' handling of XML parameters. This issue was addressed by disabling XML parameters in the Rails implementation used by Profile Manager. CVE-ID CVE-2013-0156 QuickTime Available for: Mac OS X 10.6.8, Mac OS X Server 10.6.8, OS X Lion v10.7 to v10.7.5, OS X Lion Server v10.7 to v10.7.5, OS X Mountain Lion v10.8 to v10.8.2 Impact: Viewing a maliciously crafted movie file may lead to an unexpected application termination or arbitrary code execution Description: A buffer overflow existed in the handling of 'rnet' boxes in MP4 files. This issue was addressed through improved bounds checking. This issue was addressed by disabling YAML and symbols in XML parameters in Rails. This may allow a man-in-the-middle attacker to redirect connections and intercept user credentials or other sensitive information. This issue was addressed by not allowing the incorrect SSL certificates. Software Update Available for: Mac OS X 10.6.8, Mac OS X Server 10.6.8, OS X Lion v10.7 to v10.7.5, OS X Lion Server v10.7 to v10.7.5 Impact: An attacker with a privileged network position may be able to cause arbitrary code execution Description: Software Update allowed a man in the middle attacker to insert plugin content into the marketing text displayed for updates. This may allow the exploitation of a vulnerable plugin, or facilitate social engineering attacks involving plugins. This issue was addressed by preventing plugins from being loaded in Software Update's marketing text WebView. CVE-ID CVE-2013-0973 : Emilio Escobar Wiki Server Available for: OS X Lion Server v10.7 to v10.7.5 Impact: A remote attacker may be able to cause arbitrary code execution Description: A type casting issue existed in Ruby on Rails' handling of XML parameters. This issue was addressed by disabling XML parameters in the Rails implementation used by Wiki Server. CVE-ID CVE-2013-0156 Wiki Server Available for: OS X Lion Server v10.7 to v10.7.5 Impact: A remote attacker may be able to cause arbitrary code execution Description: A type casting issue existed in Ruby on Rails' handling of JSON data. This issue was addressed by switching to using the JSONGem backend for JSON parsing in the Rails implementation used by Wiki Server. If malware is found, it presents a dialog notifying the user that malware was removed. There is no indication to the user if malware is not found. Note: OS X Mountain Lion v10.8.3 includes the content of Safari 6.0.3. For further details see "About the security content of Safari 6.0.3" at http://http//support.apple.com/kb/HT5671 OS X Mountain Lion v10.8.3 and Security Update 2013-001 may be obtained from the Software Update pane in System Preferences, or Apple's Software Downloads web site: http://www.apple.com/support/downloads/ The Software Update utility will present the update that applies to your system configuration. Only one is needed, either OS X Mountain Lion v10.8.3, or Security Update 2013-001. For OS X Mountain Lion v10.8.2 The download file is named: OSXUpd10.8.3.dmg Its SHA-1 digest is: e6165572e9145ea05aac23fa30372a9b0a0bbf3c For OS X Mountain Lion v10.8 and v10.8.1 The download file is named: OSXUpdCombo10.8.3.dmg Its SHA-1 digest is: 1bc49fde5ff6e252aa7908b4cb1f9cb9c8a5fa29 For OS X Lion v10.7.5 The download file is named: SecUpd2013-001.dmg Its SHA-1 digest is: 5bc540a208c720fce3448f853d852336781e1a17 For OS X Lion Server v10.7.5 The download file is named: SecUpdSrvr2013-001.dmg Its SHA-1 digest is: e88ff36fc8e88c4c995422d3f2364c56ebe51b07 For Mac OS X v10.6.8 The download file is named: SecUpd2013-001.dmg Its SHA-1 digest is: dc52d0f7d2db6080c57c7b9252a4d85c5e178450 For Mac OS X Server v10.6.8 The download file is named: SecUpdSrvr2013-001.dmg Its SHA-1 digest is: fd7946f8d1f1bce0394b6e56c8d7387812e14694 Information will also be posted to the Apple Security Updates web site: http://support.apple.com/kb/HT1222 This message is signed with Apple's Product Security PGP key, and details are available at: https://www.apple.com/support/security/pgp/ -----BEGIN PGP SIGNATURE----- Version: GnuPG/MacGPG2 v2.0.17 (Darwin) Comment: GPGTools - http://gpgtools.org iQIcBAEBAgAGBQJRQiuBAAoJEPefwLHPlZEwGfgP/0UDCn2KBop3IJ4Ad31yiG3N gH+yQl4GDONhm/HgrPWGQgcuVI69FmAqk+7arwOL7+7hlsSDQ5uSWDraRdd0EPmO aq2DxPxt6bYi4fHSrfkvRblVr/PcPxswEEshM82JU60Oy88EDA87bI8yy4qi8KJ4 E8+6O31vLuUeAaHf0SNE8y1p2iKpdmHH/Afo0iAVx3ddm8e8wMVPZ9XbR02pe8MV qmMWj8icBLNyHGoSl48zm5t4Ah4MS9qgXNjsYY+Mq2AcrqQI5EFTbdWpKFM7SQ1G UcM6zmeHtKNz8H21MDYKg1UHjo49MZnFb6ahRXN0E3jsPrfO4Co/2t6ogOLRZ90X 2Sd1RfwqYnRZRfwyOAe3htBYDpVEfvU1eaNMoTTHLRKWgarxUoXvww2cjnomAg5y tg+btVeQfzdHu+yClvioCbYqblKKxJf8lmhiLEgoH2bRaz2L+fluWW9yGQarxmrb vQ+cMKuy7heyLpNhwRHZioo4/b2K/IZBnkKwH76Ey3yAXnSSAD9xwbFZZAU5J8YQ liULOm9tv1sUlNHMyTsjplIsFkAIrkl+H43hn3/A+q4TIsDkmtPvOOl4Rc9/5w8H ZibyLnmr1XgXvd6CgFzIvl7Ink+d/xGHTnlybHszCMzR5o6Rg7sTeQsD34aNymcc Lz1nnBtRAbfDgARdRX4e =WUBR -----END PGP SIGNATURE-----

Trust: 2.97

sources: NVD: CVE-2013-0971 // JVNDB: JVNDB-2013-001852 // ZDI: ZDI-13-055 // BID: 58494 // BID: 58509 // VULHUB: VHN-60973 // PACKETSTORM: 120820

AFFECTED PRODUCTS

vendor:applemodel:mac os xscope:eqversion:10.6.8

Trust: 1.8

vendor:applemodel:mac os x serverscope:eqversion:10.7.0

Trust: 1.6

vendor:applemodel:mac os xscope:eqversion:10.7.2

Trust: 1.6

vendor:applemodel:mac os xscope:eqversion:10.7.3

Trust: 1.6

vendor:applemodel:mac os xscope:eqversion:10.7.4

Trust: 1.6

vendor:applemodel:mac os x serverscope:eqversion:10.7.1

Trust: 1.6

vendor:applemodel:mac os xscope:eqversion:10.8.1

Trust: 1.6

vendor:applemodel:mac os xscope:eqversion:10.8.0

Trust: 1.6

vendor:applemodel:mac os xscope:eqversion:10.7.0

Trust: 1.6

vendor:applemodel:mac os x serverscope:eqversion:10.7.4

Trust: 1.6

vendor:applemodel:mac os xscope:eqversion:10.8.2

Trust: 1.6

vendor:applemodel:mac os x serverscope:eqversion:10.7.2

Trust: 1.0

vendor:applemodel:mac os x serverscope:eqversion:10.7.5

Trust: 1.0

vendor:applemodel:mac os xscope:eqversion:10.7.5

Trust: 1.0

vendor:applemodel:mac os x serverscope:eqversion:10.7.3

Trust: 1.0

vendor:applemodel:mac os xscope:eqversion:10.7.1

Trust: 1.0

vendor:applemodel:mac os x serverscope:eqversion:10.6.8

Trust: 1.0

vendor:applemodel:mac os xscope:eqversion:server 10.6.8

Trust: 0.8

vendor:applemodel:mac os xscope:eqversion:server v10.7 to v10.7.5

Trust: 0.8

vendor:applemodel:mac os xscope:eqversion:v10.7 to v10.7.5

Trust: 0.8

vendor:applemodel:mac os xscope:eqversion:v10.8 to v10.8.2

Trust: 0.8

vendor:applemodel:os xscope: - version: -

Trust: 0.7

vendor:applemodel:mac os serverscope:eqversion:x10.7.4

Trust: 0.6

vendor:applemodel:mac os serverscope:eqversion:x10.7.3

Trust: 0.6

vendor:applemodel:mac os serverscope:eqversion:x10.7.2

Trust: 0.6

vendor:applemodel:mac os serverscope:eqversion:x10.7.1

Trust: 0.6

vendor:applemodel:mac os serverscope:eqversion:x10.7

Trust: 0.6

vendor:applemodel:mac os serverscope:eqversion:x10.6.8

Trust: 0.6

vendor:applemodel:mac osscope:eqversion:x10.7.4

Trust: 0.6

vendor:applemodel:mac osscope:eqversion:x10.7.3

Trust: 0.6

vendor:applemodel:mac osscope:eqversion:x10.7.2

Trust: 0.6

vendor:applemodel:mac osscope:eqversion:x10.7.1

Trust: 0.6

sources: ZDI: ZDI-13-055 // BID: 58494 // BID: 58509 // JVNDB: JVNDB-2013-001852 // CNNVD: CNNVD-201303-314 // NVD: CVE-2013-0971

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2013-0971
value: MEDIUM

Trust: 1.0

NVD: CVE-2013-0971
value: MEDIUM

Trust: 0.8

ZDI: CVE-2013-0971
value: MEDIUM

Trust: 0.7

CNNVD: CNNVD-201303-314
value: MEDIUM

Trust: 0.6

VULHUB: VHN-60973
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2013-0971
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:M/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.6
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 2.5

VULHUB: VHN-60973
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:M/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.6
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: ZDI: ZDI-13-055 // VULHUB: VHN-60973 // JVNDB: JVNDB-2013-001852 // CNNVD: CNNVD-201303-314 // NVD: CVE-2013-0971

PROBLEMTYPE DATA

problemtype:CWE-399

Trust: 1.9

sources: VULHUB: VHN-60973 // JVNDB: JVNDB-2013-001852 // NVD: CVE-2013-0971

THREAT TYPE

network

Trust: 0.6

sources: BID: 58494 // BID: 58509

TYPE

Unknown

Trust: 0.6

sources: BID: 58494 // BID: 58509

CONFIGURATIONS

sources: JVNDB: JVNDB-2013-001852

PATCH

title:APPLE-SA-2013-03-14-1url:http://lists.apple.com/archives/security-announce/2013/Mar/msg00002.html

Trust: 0.8

title:HT5672url:https://support.apple.com/kb/HT5672

Trust: 0.8

title:HT5672url:http://support.apple.com/kb/HT5672?viewlocale=ja_JP

Trust: 0.8

title:Apple has issued an update to correct this vulnerability.url:http://support.apple.com/kb/HT1222

Trust: 0.7

sources: ZDI: ZDI-13-055 // JVNDB: JVNDB-2013-001852

EXTERNAL IDS

db:NVDid:CVE-2013-0971

Trust: 3.6

db:BIDid:58494

Trust: 0.9

db:JVNid:JVNVU90360497

Trust: 0.8

db:JVNDBid:JVNDB-2013-001852

Trust: 0.8

db:ZDI_CANid:ZDI-CAN-1518

Trust: 0.7

db:ZDIid:ZDI-13-055

Trust: 0.7

db:CNNVDid:CNNVD-201303-314

Trust: 0.7

db:SECUNIAid:52643

Trust: 0.6

db:APPLEid:APPLE-SA-2013-03-14-1

Trust: 0.6

db:BIDid:58509

Trust: 0.4

db:SEEBUGid:SSVID-60683

Trust: 0.1

db:VULHUBid:VHN-60973

Trust: 0.1

db:PACKETSTORMid:120820

Trust: 0.1

sources: ZDI: ZDI-13-055 // VULHUB: VHN-60973 // BID: 58494 // BID: 58509 // JVNDB: JVNDB-2013-001852 // PACKETSTORM: 120820 // CNNVD: CNNVD-201303-314 // NVD: CVE-2013-0971

REFERENCES

url:http://lists.apple.com/archives/security-announce/2013/mar/msg00002.html

Trust: 1.7

url:http://support.apple.com/kb/ht1222

Trust: 0.8

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2013-0971

Trust: 0.8

url:http://jvn.jp/cert/jvnvu90360497/index.html

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2013-0971

Trust: 0.8

url:http://www.apple.com

Trust: 0.6

url:http://secunia.com/advisories/52643

Trust: 0.6

url:http://www.securityfocus.com/bid/58494

Trust: 0.6

url:https://nvd.nist.gov/vuln/detail/cve-2012-3525

Trust: 0.1

url:http://http//support.apple.com/kb/ht5671

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-0976

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-3488

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-0966

Trust: 0.1

url:http://www.apple.com/support/downloads/

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-2088

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-0156

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-0969

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-0970

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-0967

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-0971

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-0973

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-3749

Trust: 0.1

url:https://www.apple.com/support/security/pgp/

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-0333

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-3058

Trust: 0.1

url:http://gpgtools.org

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-3756

Trust: 0.1

url:http://www.postgresql.org/docs/9.1/static/release-9-1-5.html

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-3489

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-0963

Trust: 0.1

sources: ZDI: ZDI-13-055 // VULHUB: VHN-60973 // BID: 58494 // BID: 58509 // JVNDB: JVNDB-2013-001852 // PACKETSTORM: 120820 // CNNVD: CNNVD-201303-314 // NVD: CVE-2013-0971

CREDITS

Apple, Clint Ruoho of Laconic Security, an anonymous researcher, Eric A. Schulman of Purpletree Labs, Aaron Sigel of vtty.com, Tobias Klein working with HP TippingPoint's Zero Day Initiative, and Emilio Escobar

Trust: 0.9

sources: BID: 58494 // CNNVD: CNNVD-201303-314

SOURCES

db:ZDIid:ZDI-13-055
db:VULHUBid:VHN-60973
db:BIDid:58494
db:BIDid:58509
db:JVNDBid:JVNDB-2013-001852
db:PACKETSTORMid:120820
db:CNNVDid:CNNVD-201303-314
db:NVDid:CVE-2013-0971

LAST UPDATE DATE

2025-04-11T21:41:24.423000+00:00


SOURCES UPDATE DATE

db:ZDIid:ZDI-13-055date:2013-04-09T00:00:00
db:VULHUBid:VHN-60973date:2013-03-18T00:00:00
db:BIDid:58494date:2013-03-15T17:05:00
db:BIDid:58509date:2013-04-09T15:48:00
db:JVNDBid:JVNDB-2013-001852date:2013-03-19T00:00:00
db:CNNVDid:CNNVD-201303-314date:2013-03-18T00:00:00
db:NVDid:CVE-2013-0971date:2025-04-11T00:51:21.963

SOURCES RELEASE DATE

db:ZDIid:ZDI-13-055date:2013-04-09T00:00:00
db:VULHUBid:VHN-60973date:2013-03-15T00:00:00
db:BIDid:58494date:2013-03-14T00:00:00
db:BIDid:58509date:2013-03-14T00:00:00
db:JVNDBid:JVNDB-2013-001852date:2013-03-19T00:00:00
db:PACKETSTORMid:120820date:2013-03-15T22:23:48
db:CNNVDid:CNNVD-201303-314date:2013-03-15T00:00:00
db:NVDid:CVE-2013-0971date:2013-03-15T20:55:11.350