HIGH · 7.2

CVE-2005-1387

Cocktail 3.5.4 and possibly earlier in Mac OS X passes the administrative password on the command line to sudo in cleartext, which allows local users to gain sensitive information by running listing p...

Vulnerability Description

Cocktail 3.5.4 and possibly earlier in Mac OS X passes the administrative password on the command line to sudo in cleartext, which allows local users to gain sensitive information by running listing processes.

CVSS Score

7.2

HIGH

AV:L/AC:L/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
Kristofer SzymanskiCocktail3.5.4

References

FAQ

What is CVE-2005-1387?

CVE-2005-1387 is a vulnerability with a CVSS score of 7.2 (HIGH). Cocktail 3.5.4 and possibly earlier in Mac OS X passes the administrative password on the command line to sudo in cleartext, which allows local users to gain sensitive information by running listing p...

How severe is CVE-2005-1387?

CVE-2005-1387 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2005-1387?

Check the references section above for vendor advisories and patch information. Affected products include: Kristofer Szymanski Cocktail.