CVE-2005-2742
Summary
| CVE | CVE-2005-2742 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2005-10-26 00:02:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | SecurityAgent in Apple Mac OS X 10.4.2, under certain circumstances, can cause the "Switch User..." button to appear even though the "Enable fast user switching" setting is disabled, which can allow attackers with physical access to gain access to the desktop and bypass the "Require password to wake this computer from sleep or screen saver" setting. |
Risk And Classification
Primary CVSS: v2.0 4.6 from [email protected]
AV:L/AC:L/Au:N/C:P/I:P/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:L/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Apple | Mac Os X | 10.4.2 | All | All | All |
| Operating System | Apple | Mac Os X Server | 10.4.2 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| AusCERT - ESB-2005.0732 -- APPLE-SA-2005-09-22 -- Security Update 2005-008 | af854a3a-2127-422b-91ae-364da2661108 | www.auscert.org.au | Vendor Advisory |
| Secunia - Advisories - Mac OS X Security Update Fixes Multiple Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Patch, Vendor Advisory |
| APPLE-SA-2005-09-22 Security Update 2005-008 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | Vendor Advisory |
| P-312: Apple Security Update 2005-008 | af854a3a-2127-422b-91ae-364da2661108 | www.ciac.org | US Government Resource |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.