PT-2006-5203 · Apple · Workgroup Manager+2
Chris Pepper
·
Published
2006-10-02
·
Updated
2017-07-20
·
CVE-2006-4399
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Apple Mac OS X versions 10.4 through 10.4.7
Description
The issue is related to an inconsistency in the Workgroup Manager user interface, which may lead to less secure password management. Administrators may be allowed to change the authentication type from crypt to ShadowHash passwords for accounts in a NetInfo parent, even though this operation is not supported.
Recommendations
For Apple Mac OS X versions 10.4 through 10.4.7, avoid using the Workgroup Manager to change the authentication type from crypt to ShadowHash passwords for accounts in a NetInfo parent, as this operation is not actually supported and may result in less secure password management.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Macos X
Netinfo
Workgroup Manager