MacOS 9 Console Lock Bypass Vulnerability
BID:745
Info
MacOS 9 Console Lock Bypass Vulnerability
| Bugtraq ID: | 745 |
| Class: | Design Error |
| CVE: |
CVE-1999-1076 |
| Remote: | No |
| Local: | Yes |
| Published: | Oct 26 1999 12:00AM |
| Updated: | Jul 11 2009 12:56AM |
| Credit: | Posted to Bugtraq by Sean Sosik-Hamor <[email protected]> on October 26, 1999. |
| Vulnerable: |
Apple Mac OS 9 9.0 |
| Not Vulnerable: | |
Discussion
MacOS 9 Console Lock Bypass Vulnerability
MacOS 9 includes an idle-activated console lock feature, similar to a screensaver password in other operating systems. After a certain length of user inactivity, a dialog box appears stating that a password must be entered. After the user clicks 'OK' another dialog box appears offering the option to either supply a password or to log out the current user. If the 'log out' option is chosen, any programs running will start to shut down. In certain programs, dialog boxes are created in the shutdown process (for example, "Exit without saving? OK/Cancel"). If the user selects 'Cancel', the shutdown process is aborted and the user is returned to the current session without ever having to enter a password.
MacOS 9 includes an idle-activated console lock feature, similar to a screensaver password in other operating systems. After a certain length of user inactivity, a dialog box appears stating that a password must be entered. After the user clicks 'OK' another dialog box appears offering the option to either supply a password or to log out the current user. If the 'log out' option is chosen, any programs running will start to shut down. In certain programs, dialog boxes are created in the shutdown process (for example, "Exit without saving? OK/Cancel"). If the user selects 'Cancel', the shutdown process is aborted and the user is returned to the current session without ever having to enter a password.
Exploit / POC
MacOS 9 Console Lock Bypass Vulnerability
See Discussion
See Discussion
Solution / Fix
MacOS 9 Console Lock Bypass Vulnerability
Solution:
Apple has been notified, and It has been filed into their bug database as ID #2405549.
Currently the SecurityFocus staff are not aware of any vendor supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Apple has been notified, and It has been filed into their bug database as ID #2405549.
Currently the SecurityFocus staff are not aware of any vendor supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
MacOS 9 Console Lock Bypass Vulnerability
References:
References: