First published: Fri Jun 13 2003(Updated: )
Information leak in dsimportexport for Apple Macintosh OS X Server 10.2.6 allows local users to obtain the username and password of the account running the tool.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Mac OS X Server | =10.2.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-0420 is considered a medium severity vulnerability due to the potential exposure of sensitive user credentials.
Local users can exploit CVE-2003-0420 by using the dsimportexport tool to extract usernames and passwords from running processes.
CVE-2003-0420 affects Apple Mac OS X Server version 10.2.6.
Mitigation for CVE-2003-0420 involves restricting access to the dsimportexport tool, ensuring that only authorized users can execute it.
There is no official patch for CVE-2003-0420, so users should consider upgrading to a later version of the operating system.