Race condition in LoginWindow in Apple OS X before 10.10 allows physically proximate attackers to obtain access by leveraging an unattended workstation on which screen locking had been attempted.
The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/70622 | vdb entry |
http://archives.neohapsis.com/archives/bugtraq/2014-10/0101.html | vendor advisory |
http://www.securitytracker.com/id/1031063 | vdb entry |
https://support.apple.com/kb/HT6535 | vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/97630 | vdb entry |