PT-2006-5203 · Apple · Workgroup Manager+2

Chris Pepper

·

Published

2006-10-02

·

Updated

2017-07-20

·

CVE-2006-4399

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Apple Mac OS X versions 10.4 through 10.4.7
Description The issue is related to an inconsistency in the Workgroup Manager user interface, which may lead to less secure password management. Administrators may be allowed to change the authentication type from crypt to ShadowHash passwords for accounts in a NetInfo parent, even though this operation is not supported.
Recommendations For Apple Mac OS X versions 10.4 through 10.4.7, avoid using the Workgroup Manager to change the authentication type from crypt to ShadowHash passwords for accounts in a NetInfo parent, as this operation is not actually supported and may result in less secure password management.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-4399

Affected Products

Macos X
Netinfo
Workgroup Manager