The CoreProcesses component in Apple Mac OS X 10.7 before 10.7.2 does not prevent a system window from receiving keystrokes in the locked-screen state, which might allow physically proximate attackers to bypass intended access restrictions by typing into this window.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.html | vendor advisory |
http://support.apple.com/kb/HT5002 | vendor advisory |
http://www.securityfocus.com/bid/50085 | vdb entry |