CVE-2010-0512
Summary
| CVE | CVE-2010-0512 |
|---|---|
| State | PUBLISHED |
| Assigner | apple |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-03-30 18:30:00 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | The Accounts Preferences implementation in Apple Mac OS X 10.6 before 10.6.3, when a network account server is used, does not support Login Window access control that is based solely on group membership, which allows attackers to bypass intended access restrictions by entering login credentials. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:M/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Apple | Mac Os X | 10.6.0 | All | All | All |
| Operating System | Apple | Mac Os X | 10.6.1 | All | All | All |
| Operating System | Apple | Mac Os X | 10.6.2 | All | All | All |
| Operating System | Apple | Mac Os X Server | 10.6.0 | All | All | All |
| Operating System | Apple | Mac Os X Server | 10.6.1 | All | All | All |
| Operating System | Apple | Mac Os X Server | 10.6.2 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| APPLE-SA-2010-03-29-1 Security Update 2010-002 / Mac OS X v10.6.3 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | Patch, Vendor Advisory |
| About the security content of Security Update 2010-002 / Mac OS X v10.6.3 | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | Patch, Vendor Advisory |
| Apple Mac OS X Preferences System Login Restrictions Authentication Bypass Security Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.