Description
Login Window in Apple Mac OS X 10.4.11 does not clear the current password when a user makes a password-change attempt that is denied by policy, which allows opportunistic, physically proximate attackers to bypass authentication and change this user's password by later entering an acceptable new password on the same login screen.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2008-3597 | Login Window in Apple Mac OS X 10.4.11 does not clear the current password when a user makes a password-change attempt that is denied by policy, which allows opportunistic, physically proximate attackers to bypass authentication and change this user's password by later entering an acceptable new password on the same login screen. |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T09:45:18.935Z
Reserved: 2008-08-12T00:00:00.000Z
Link: CVE-2008-3611
No data.
Status : Modified
Published: 2008-09-16T23:00:01.133
Modified: 2026-04-23T00:35:47.467
Link: CVE-2008-3611
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD