dscl in DS Tools in Apple Mac OS X 10.4.11 and 10.5.6 requires that passwords must be provided as command line arguments, which allows local users to gain privileges by listing process information.
Weaknesses in this category are related to the management of credentials.
Link | Tags |
---|---|
http://secunia.com/advisories/33937 | third party advisory |
http://securitytracker.com/alerts/2009/Feb/1021722.html | vdb entry |
http://www.securityfocus.com/bid/33759 | vdb entry |
http://support.apple.com/kb/HT3438 | |
http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html | patch vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/48717 | vdb entry |
http://www.vupen.com/english/advisories/2009/0422 | vdb entry |
http://www.securityfocus.com/bid/33815 | vdb entry |