Vulnerability Description
The Accounts Preferences implementation in Apple Mac OS X 10.6 before 10.6.3, when a network account server is used, does not support Login Window access control that is based solely on group membership, which allows attackers to bypass intended access restrictions by entering login credentials.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apple | Mac Os X | 10.6.0 |
| Apple | Mac Os X Server | 10.6.0 |
Related Weaknesses (CWE)
References
- http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.htmlPatchVendor Advisory
- http://support.apple.com/kb/HT4077PatchVendor Advisory
- http://www.securityfocus.com/bid/39153
- http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.htmlPatchVendor Advisory
- http://support.apple.com/kb/HT4077PatchVendor Advisory
- http://www.securityfocus.com/bid/39153
FAQ
What is CVE-2010-0512?
CVE-2010-0512 is a vulnerability with a CVSS score of 9.3 (HIGH). The Accounts Preferences implementation in Apple Mac OS X 10.6 before 10.6.3, when a network account server is used, does not support Login Window access control that is based solely on group membersh...
How severe is CVE-2010-0512?
CVE-2010-0512 has been rated HIGH with a CVSS base score of 9.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2010-0512?
Check the references section above for vendor advisories and patch information. Affected products include: Apple Mac Os X, Apple Mac Os X Server.