CVE Vulnerabilities

CVE-2008-3611

Improper Authentication

Published: Sep 16, 2008 | Modified: Aug 08, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.3 MEDIUM
AV:L/AC:M/Au:N/C:N/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Login Window in Apple Mac OS X 10.4.11 does not clear the current password when a user makes a password-change attempt that is denied by policy, which allows opportunistic, physically proximate attackers to bypass authentication and change this users password by later entering an acceptable new password on the same login screen.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Mac_os_x Apple 10.4.11 (including) 10.4.11 (including)
Mac_os_x_server Apple 10.4.11 (including) 10.4.11 (including)

Potential Mitigations

References