CFNetwork in Apple OS X through 10.8.5 does not remove session cookies upon a Safari reset action, which allows physically proximate attackers to bypass intended access restrictions by leveraging an unattended workstation.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Mac_os_x | Apple | 10.8.0 | 10.8.0 |
Mac_os_x | Apple | 10.8.1 | 10.8.1 |
Mac_os_x | Apple | 10.8.2 | 10.8.2 |
Mac_os_x | Apple | 10.8.3 | 10.8.3 |
Mac_os_x | Apple | 10.8.4 | 10.8.4 |
Mac_os_x | Apple | 10.8.5 | 10.8.5 |
Mac_os_x | Apple | * | 10.8.5 |