First published: Fri Jun 06 2003(Updated: )
The Kerberos login authentication feature in Mac OS X, when used with an LDAPv3 server and LDAP bind authentication, may send cleartext passwords to the LDAP server when the AuthenticationAuthority attribute is not set.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
macOS Yosemite | <=10.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-0378 is considered a medium severity vulnerability due to the transmission of cleartext passwords.
To resolve CVE-2003-0378, you should configure the AuthenticationAuthority attribute in your Kerberos configuration to avoid sending cleartext passwords.
CVE-2003-0378 affects Mac OS X versions up to 10.2.
CVE-2003-0378 can lead to the exposure of user passwords, compromising LDAP authentication security.
CVE-2003-0378 could potentially be exploited remotely if an attacker can intercept the network traffic between the client and the LDAP server.