NSSecureTextField in AppKit in Apple Mac OS X 10.4.6 does not re-enable secure event input under certain circumstances, which could allow other applications in the window session to monitor input characters and keyboard events.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/17951 | vdb entry |
http://www.vupen.com/english/advisories/2006/1779 | vdb entry vendor advisory |
http://www.us-cert.gov/cas/techalerts/TA06-132A.html | third party advisory us government resource |
https://exchange.xforce.ibmcloud.com/vulnerabilities/26404 | vdb entry |
http://lists.apple.com/archives/security-announce/2006/May/msg00003.html | patch vendor advisory |
http://secunia.com/advisories/20077 | third party advisory vendor advisory |
http://www.osvdb.org/25583 | vdb entry |