Podcast Capture in Podcast Producer for Apple Mac OS X 10.5.2 invokes a subtask with passwords in command line arguments, which allows local users to read the passwords via process listings.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/28304 | vdb entry |
http://www.us-cert.gov/cas/techalerts/TA08-079A.html | third party advisory us government resource |
http://www.vupen.com/english/advisories/2008/0924/references | vdb entry |
http://www.securityfocus.com/bid/28372 | vdb entry |
http://secunia.com/advisories/29420 | third party advisory |
http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html | patch vendor advisory |
http://www.securitytracker.com/id?1019664 | vdb entry |
http://docs.info.apple.com/article.html?artnum=307562 |