First published: Sat Dec 31 2005(Updated: )
Mac OS X 10.4.3 up to 10.4.6, when loginwindow uses the "Name and password" setting, and the "Show the Restart, Sleep, and Shut Down buttons" option is disabled, allows users with physical access to bypass login and reboot the system by entering ">restart", ">power", or ">shutdown" sequences after the username.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
macOS Yosemite | =10.4.3 | |
Apple Mac OS X Server | =10.4.3 | |
Apple Mac OS X Server | =10.4.4 | |
macOS Yosemite | =10.4.4 | |
Apple Mac OS X Server | =10.4.5 | |
Apple Mac OS X Server | =10.4.6 | |
macOS Yosemite | =10.4.6 | |
macOS Yosemite | =10.4.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-3782 has been assigned a medium severity rating as it allows local users to bypass login security.
To fix CVE-2005-3782, you should ensure that the 'Show the Restart, Sleep, and Shut Down buttons' option is enabled in the login window settings.
CVE-2005-3782 affects Mac OS X versions 10.4.3 through 10.4.6.
No, CVE-2005-3782 requires physical access to the machine to exploit the vulnerability.
CVE-2005-3782 allows a local user to execute restart, shutdown, or power commands without logging in.