The sso_util program in Single Sign-On in Apple Mac OS X before 10.5.3 places passwords on the command line, which allows local users to obtain sensitive information by listing the process.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/29520 | vdb entry |
http://www.us-cert.gov/cas/techalerts/TA08-150A.html | us government resource third party advisory patch |
http://secunia.com/advisories/30430 | third party advisory vendor advisory |
http://lists.apple.com/archives/security-announce/2008//May/msg00001.html | patch vendor advisory |
http://www.vupen.com/english/advisories/2008/1697 | vdb entry vendor advisory |
http://www.securityfocus.com/bid/29412 | vdb entry |
http://securitytracker.com/id?1020142 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/42725 | vdb entry |