First published: Fri Aug 19 2005(Updated: )
The password assistant in Mac OS X 10.4 to 10.4.2, when used to create multiple accounts from the same process, does not reset the suggested password list when the assistant is displayed, which allows attackers to view recently used passwords.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
macOS Yosemite | =10.4.1 | |
macOS Yosemite | =10.4 | |
macOS Yosemite | =10.4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-2520 is considered a moderate severity vulnerability due to potential password exposure.
To fix CVE-2005-2520, upgrade to a later version of Mac OS X that addresses this vulnerability.
CVE-2005-2520 affects Mac OS X versions 10.4, 10.4.1, and 10.4.2.
The impact of CVE-2005-2520 allows attackers to view recently used passwords through the password assistant.
CVE-2005-2520 requires local access to exploit, as it involves the local password assistant interface.