Apple Xsan Admin Error Message Information Disclosure Vulnerability
BID:36385
Info
Apple Xsan Admin Error Message Information Disclosure Vulnerability
| Bugtraq ID: | 36385 |
| Class: | Design Error |
| CVE: |
CVE-2009-2201 |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 14 2009 12:00AM |
| Updated: | Sep 14 2009 07:11PM |
| Credit: | Ben Greisler of Kadimac Corp Macintosh Integrators |
| Vulnerable: |
Apple Xsan 2.1.1 |
| Not Vulnerable: |
Apple Xsan 2.2 |
Discussion
Apple Xsan Admin Error Message Information Disclosure Vulnerability
Apple Xsan is prone to an information-disclosure vulnerability affecting the Xsan Admin component.
Successful exploits may allow attackers with physical access to an affected computer to obtain password data. Information harvested may aid in launching further attacks.
Versions prior to Xsan 2.2 are vulnerable.
Apple Xsan is prone to an information-disclosure vulnerability affecting the Xsan Admin component.
Successful exploits may allow attackers with physical access to an affected computer to obtain password data. Information harvested may aid in launching further attacks.
Versions prior to Xsan 2.2 are vulnerable.
Exploit / POC
Apple Xsan Admin Error Message Information Disclosure Vulnerability
To exploit this issue, an attacker requires physical access to an affected computer.
To exploit this issue, an attacker requires physical access to an affected computer.
Solution / Fix
Apple Xsan Admin Error Message Information Disclosure Vulnerability
Solution:
The vendor has released an advisory and fixes. Please see the references for details.
Apple Xsan 2.1.1
Solution:
The vendor has released an advisory and fixes. Please see the references for details.
Apple Xsan 2.1.1
-
Apple XsanAdminUpdateLeopard.dmg
for Mac OS X 10.5.8
http://www.apple.com/support/downloads/ -
Apple XsanAdminUpdateSnowLeo.dmg
for Mac OS X 10.6
http://www.apple.com/support/downloads/
References
Apple Xsan Admin Error Message Information Disclosure Vulnerability
References:
References:
- Xsan Homepage (Apple)