PT-2006-2447 · Apple · Appkit+1
Published
2006-05-12
·
Updated
2017-07-20
·
CVE-2006-1439
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
AppKit in Apple Mac OS X version 10.4.6
Description
The issue concerns NSSecureTextField in AppKit, which fails to re-enable secure event input under certain circumstances. This could allow other applications in the same window session to monitor input characters and keyboard events.
Recommendations
For AppKit in Apple Mac OS X version 10.4.6, consider applying configuration changes to restrict access to sensitive input fields until a fix is available. As a temporary workaround, avoid using NSSecureTextField in applications where secure input is crucial, to minimize the risk of input character and keyboard event monitoring.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Appkit
Macos X