The password assistant in Mac OS X 10.4 to 10.4.2, when used to create multiple accounts from the same process, does not reset the suggested password list when the assistant is displayed, which allows attackers to view recently used passwords.
Link | Tags |
---|---|
http://securitytracker.com/id?1014707 | vdb entry |
http://lists.apple.com/archives/security-announce/2005/Aug/msg00000.html | patch vendor advisory |
http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html | patch vendor advisory |