PT-2001-2649 · Macos · Pppd

Published

2001-12-31

·

Updated

2008-09-05

·

CVE-2001-1565

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions pppd in MacOS x versions 10.0 through 10.1.5
Description The issue allows local users to obtain authentication information, including usernames and passwords, by accessing the command line arguments of the Point to Point Protocol daemon (pppd) process via the ps command.
Recommendations For MacOS x versions 10.0 through 10.1.5, consider restricting access to the ps command or the pppd process to minimize the risk of exploitation. As a temporary workaround, avoid using the pppd daemon until a patch is available or apply configuration changes to prevent local users from accessing sensitive authentication information.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2001-1565

Affected Products

Pppd