PT-2006-2447 · Apple · Appkit+1
Publicado
2006-05-12
·
Atualizado
2017-07-20
·
CVE-2006-1439
CVSS v2.0
2.1
Baixa
| Vetor | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
AppKit in Apple Mac OS X version 10.4.6
Description
The issue concerns NSSecureTextField in AppKit, which fails to re-enable secure event input under certain circumstances. This could allow other applications in the same window session to monitor input characters and keyboard events.
Recommendations
For AppKit in Apple Mac OS X version 10.4.6, consider applying configuration changes to restrict access to sensitive input fields until a fix is available. As a temporary workaround, avoid using NSSecureTextField in applications where secure input is crucial, to minimize the risk of input character and keyboard event monitoring.
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Appkit
Macos X