PT-2005-2469 · Apple · Macos X

Published

2005-06-09

·

Updated

2008-09-05

·

CVE-2005-1473

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Apple Mac OS X version 10.4.1
Description: The issue allows attackers with physical access to bypass the locked screensaver and launch background applications. This can be achieved by opening a URL from a text input field, exploiting the SecurityAgent component.
Recommendations: For Apple Mac OS X version 10.4.1, consider restricting physical access to devices to minimize the risk of exploitation. As a temporary workaround, avoid using the text input field to open URLs when the screensaver is locked.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-1473

Affected Products

Macos X