slapconfig in Directory Services in Apple Mac OS X 10.5 through 10.5.4 allows local users to select a readable output file into which the server password will be written by an OpenLDAP system administrator, related to the mkfifo function, aka an "insecure file operation issue."
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/31189 | patch vdb entry |
http://lists.apple.com/archives/security-announce//2008/Sep/msg00005.html | patch vendor advisory |
http://www.us-cert.gov/cas/techalerts/TA08-260A.html | third party advisory us government resource |
http://www.vupen.com/english/advisories/2008/2584 | vdb entry |
http://secunia.com/advisories/31882 | third party advisory |
http://securitytracker.com/id?1020874 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/45164 | vdb entry |