[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248038

 
 

909

 
 

194772

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2008-3611Date: (C)2008-09-16   (M)2023-12-22


Login Window in Apple Mac OS X 10.4.11 does not clear the current password when a user makes a password-change attempt that is denied by policy, which allows opportunistic, physically proximate attackers to bypass authentication and change this user's password by later entering an acceptable new password on the same login screen.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 6.3
Exploit Score: 3.4
Impact Score: 9.2
 
CVSS V2 Metrics:
Access Vector: LOCAL
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: NONE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
SECTRACK-1020878
BID-31189
SECUNIA-31882
ADV-2008-2584
APPLE-SA-2008-09-15
TA08-260A
macos-loginscreen-security-bypass(45171)

CPE    2
cpe:/o:apple:mac_os_x_server:10.4.11
cpe:/o:apple:mac_os_x:10.4.11
CWE    1
CWE-287

© SecPod Technologies