Apple MacOS Multiple Users Password Bypass Vulnerability
BID:2685
Info
Apple MacOS Multiple Users Password Bypass Vulnerability
| Bugtraq ID: | 2685 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | May 03 2001 12:00AM |
| Updated: | May 03 2001 12:00AM |
| Credit: | Reported to bugtraq by Adam Franke <[email protected]> on May 3, 2001. |
| Vulnerable: |
Apple Mac OS 9 9.0 |
| Not Vulnerable: | |
Discussion
Apple MacOS Multiple Users Password Bypass Vulnerability
MacOS implements secure support for a system hosting many users by means of the Multiple Users program.
Versions of MacOS 9 contain a flaw allowing the Multiple Users facility to be entirely bypassed.
A local user may exploit this vulnerability to gain unrestricted access to the affected host's filesystem, user configuration, and other sensitive system information.
MacOS implements secure support for a system hosting many users by means of the Multiple Users program.
Versions of MacOS 9 contain a flaw allowing the Multiple Users facility to be entirely bypassed.
A local user may exploit this vulnerability to gain unrestricted access to the affected host's filesystem, user configuration, and other sensitive system information.
Exploit / POC
Apple MacOS Multiple Users Password Bypass Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Apple MacOS Multiple Users Password Bypass Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Apple MacOS Multiple Users Password Bypass Vulnerability
References:
References: