CVE-2004-1081: Low severity Apple Darwin Streaming Server vulnerability
Published Dec 2, 2004
·Updated
The Application Framework (AppKit) for Apple Mac OS X 10.2.8 and 10.3.6 does not properly restrict access to a secure text input field, which allows local users to read keyboard input from other applications within the same window session.
Affected Software
35 affected components
Apple Darwin Streaming Server=4.1.3
Apple Darwin Streaming Server=5.0.1
Apple Quicktime Streaming Server=4.1.1
Apple iOS and macOS=10.2
Apple iOS and macOS=10.2.1
Apple iOS and macOS=10.2.2
Apple iOS and macOS=10.2.3
Apple iOS and macOS=10.2.4
Apple iOS and macOS=10.2.5
Apple iOS and macOS=10.2.6
Apple iOS and macOS=10.2.7
Apple iOS and macOS=10.2.8
Apple iOS and macOS=10.3
Apple iOS and macOS=10.3.1
Apple iOS and macOS=10.3.2
Apple iOS and macOS=10.3.3
Apple iOS and macOS=10.3.4
Apple iOS and macOS=10.3.5
Apple iOS and macOS=10.3.6
Apple Mac OS X Server=10.2
Apple Mac OS X Server=10.2.1
Apple Mac OS X Server=10.2.2
Apple Mac OS X Server=10.2.3
Apple Mac OS X Server=10.2.4
Apple Mac OS X Server=10.2.5
Apple Mac OS X Server=10.2.6
Apple Mac OS X Server=10.2.7
Apple Mac OS X Server=10.2.8
Apple Mac OS X Server=10.3
Apple Mac OS X Server=10.3.1
Apple Mac OS X Server=10.3.2
Apple Mac OS X Server=10.3.3
Apple Mac OS X Server=10.3.4
Apple Mac OS X Server=10.3.5
Apple Mac OS X Server=10.3.6
Remediation
Patch Available
Patch Available
Patch Available
Event History
Dec 2, 2004
CVE Published
05:00 AM
Apr 14, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-1081?
CVE-2004-1081 has been classified as a potential local security vulnerability due to improper access restrictions.
2
How do I fix CVE-2004-1081?
To mitigate CVE-2004-1081, users should update their Apple Mac OS X systems to the latest security patch available.
3
Who is affected by CVE-2004-1081?
CVE-2004-1081 affects local users running Apple Mac OS X versions 10.2.8 and 10.3.6.
4
What is the impact of CVE-2004-1081?
The impact of CVE-2004-1081 allows local users to read keyboard input from other applications, posing a privacy risk.
5
When was CVE-2004-1081 reported?
CVE-2004-1081 was reported in December 2004.