First published: Mon Oct 02 2006(Updated: )
Unchecked error condition in LoginWindow in Apple Mac OS X 10.4 through 10.4.7 prevents Kerberos tickets from being destroyed if a user does not successfully log on to a network account from the login window, which might allow later users to gain access to the original user's Kerberos tickets.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
macOS Yosemite | =10.4.3 | |
macOS Yosemite | =10.4.1 | |
macOS Yosemite | =10.4.7 | |
macOS Yosemite | =10.4.4 | |
macOS Yosemite | =10.4 | |
macOS Yosemite | =10.4.6 | |
macOS Yosemite | =10.4.5 | |
macOS Yosemite | =10.4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-4397 is considered a moderate severity vulnerability due to its potential for unauthorized access to Kerberos tickets.
To fix CVE-2006-4397, it is recommended to update Apple Mac OS X to the latest version available.
CVE-2006-4397 affects Apple Mac OS X versions 10.4 through 10.4.7.
CVE-2006-4397 is an access control vulnerability that allows unauthorized users to potentially access Kerberos tickets.
Yes, CVE-2006-4397 can impact network security by allowing subsequent users to use the original user's Kerberos tickets without authentication.