CVE-2010-0512

The Accounts Preferences implementation in Apple Mac OS X 10.6 before 10.6.3, when a network account server is used, does not support Login Window access control that is based solely on group membership, which allows attackers to bypass intended access restrictions by entering login credentials.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:apple:mac_os_x:10.6.0:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.6.1:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.6.2:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x_server:10.6.0:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x_server:10.6.1:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x_server:10.6.2:*:*:*:*:*:*:*

History

21 Nov 2024, 01:12

Type Values Removed Values Added
References () http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html - Patch, Vendor Advisory () http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html - Patch, Vendor Advisory
References () http://support.apple.com/kb/HT4077 - Patch, Vendor Advisory () http://support.apple.com/kb/HT4077 - Patch, Vendor Advisory
References () http://www.securityfocus.com/bid/39153 - () http://www.securityfocus.com/bid/39153 -

Information

Published : 2010-03-30 18:30

Updated : 2024-11-21 01:12


NVD link : CVE-2010-0512

Mitre link : CVE-2010-0512

CVE.ORG link : CVE-2010-0512


JSON object : View

Products Affected

apple

  • mac_os_x
  • mac_os_x_server
CWE
CWE-264

Permissions, Privileges, and Access Controls