CVE-2006-4397: Medium severity Apple iOS and macOS vulnerability
Unchecked error condition in LoginWindow in Apple Mac OS X 10.4 through 10.4.7 prevents Kerberos tickets from being destroyed if a user does not successfully log on to a network account from the login window, which might allow later users to gain access to the original user's Kerberos tickets.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-4397?
CVE-2006-4397 is considered a moderate severity vulnerability due to its potential for unauthorized access to Kerberos tickets.
How do I fix CVE-2006-4397?
To fix CVE-2006-4397, it is recommended to update Apple Mac OS X to the latest version available.
Which versions of macOS are affected by CVE-2006-4397?
CVE-2006-4397 affects Apple Mac OS X versions 10.4 through 10.4.7.
What type of vulnerability is CVE-2006-4397?
CVE-2006-4397 is an access control vulnerability that allows unauthorized users to potentially access Kerberos tickets.
Can CVE-2006-4397 impact the security of my network?
Yes, CVE-2006-4397 can impact network security by allowing subsequent users to use the original user's Kerberos tickets without authentication.