PT-2005-3624 · Apple · Macos X
Luke Fowler
·
Published
2005-10-25
·
Updated
2008-09-05
·
CVE-2005-2742
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Apple Mac OS X version 10.4.2
Description
The issue allows attackers with physical access to bypass security settings under certain circumstances. When the "Enable fast user switching" setting is disabled, the "Switch User..." button may still appear, enabling access to the desktop. This can also bypass the "Require password to wake this computer from sleep or screen saver" setting.
Recommendations
For Apple Mac OS X version 10.4.2, consider disabling the fast user switching feature entirely to prevent unauthorized access until a fix is available. Additionally, ensure that physical access to the computer is restricted to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Macos X