PT-2006-5201 · Apple · Macos X
Patrick Gallagher
·
Published
2006-10-02
·
Updated
2011-03-08
·
CVE-2006-4397
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Apple Mac OS X versions 10.4 through 10.4.7
Description
The issue is related to an unchecked error condition in the LoginWindow of Apple Mac OS X. This condition prevents Kerberos tickets from being destroyed if a user fails to log on to a network account from the login window. As a result, later users might be able to gain access to the original user's Kerberos tickets.
Recommendations
For Apple Mac OS X versions 10.4 through 10.4.7, consider updating to a version outside of this range to mitigate the risk of unauthorized access to Kerberos tickets. As a temporary workaround, restrict access to sensitive network resources to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Macos X