CVE-2012-0652

MEDIUM

Description

Login Window in Apple Mac OS X 10.7.3, when Legacy File Vault or networked home directories are enabled, does not properly restrict what is written to the system log for network logins, which allows local users to obtain sensitive information by reading the log.

References

http://lists.apple.com/archives/security-announce/2012/May/msg00001.html

http://lists.apple.com/archives/security-announce/2012/Sep/msg00004.html

http://support.apple.com/kb/HT5281

http://support.apple.com/kb/HT5501

http://www.securityfocus.com/bid/53445

http://www.securityfocus.com/bid/53457

http://www.securitytracker.com/id?1027024

Details

Source: MITRE

Published: 2012-05-11

Updated: 2017-12-05

Type: CWE-200

Risk Information

CVSS v2.0

Base Score: 4.9

Vector: AV:L/AC:L/Au:N/C:C/I:N/A:N

Impact Score: 6.9

Exploitability Score: 3.9

Severity: MEDIUM