Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Perette Barella

Researcher fromDeviousFish.com
#42698of 53,633
6.2Total CVSS
Vulnerabilities · 1
PT-2017-1349
6.2
2017-02-20
Darpa · Openam · CVE-2016-7600
**Name of the Vulnerable Software and Affected Versions** macOS versions prior to 10.12.2 **Description** The issue involves the `OpenPAM` component, which allows local users to obtain sensitive information by leveraging mishandling of failed PAM authentication by a sandboxed app. This is related to the lack of protection for service data, allowing a local attacker to gain confidential information in connection with failed PAM authentication of a sandboxed application. **Recommendations** For macOS versions prior to 10.12.2, update to version 10.12.2 or later to resolve the issue. As a temporary workaround, consider restricting the use of the `OpenPAM` component until a patch is applied.