First published: Wed Jun 30 2004(Updated: )
Apple Mac OS X 10.3.4, 10.4, 10.5, and possibly other versions does not properly clear memory for login (aka Loginwindow.app), Keychain, or FileVault passwords, which could allow the root user or an attacker with physical access to obtain sensitive information by reading memory.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
macOS Yosemite | =10.5 | |
macOS Yosemite | =10.4 | |
macOS Yosemite | =10.3.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-0622 has a moderate severity rating due to the potential for sensitive information exposure.
To fix CVE-2004-0622, update your macOS to a version that addresses this vulnerability.
CVE-2004-0622 may expose sensitive information such as login credentials and encryption keys stored in memory.
CVE-2004-0622 affects users of Apple Mac OS X versions 10.3.4, 10.4, and 10.5.
CVE-2004-0622 can be exploited by an attacker with physical access to the machine.