CVE-2008-3611

critical

Description

Login Window in Apple Mac OS X 10.4.11 does not clear the current password when a user makes a password-change attempt that is denied by policy, which allows opportunistic, physically proximate attackers to bypass authentication and change this user's password by later entering an acceptable new password on the same login screen.

References

https://exchange.xforce.ibmcloud.com/vulnerabilities/45171

http://www.vupen.com/english/advisories/2008/2584

http://www.us-cert.gov/cas/techalerts/TA08-260A.html

http://www.securityfocus.com/bid/31189

http://securitytracker.com/id?1020878

http://secunia.com/advisories/31882

http://lists.apple.com/archives/security-announce//2008/Sep/msg00005.html

Details

Source: Mitre, NVD

Published: 2008-09-16

Risk Information

CVSS v2

Base Score: 6.3

Vector: CVSS2#AV:L/AC:M/Au:N/C:N/I:C/A:C

Severity: Medium

CVSS v3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical