First published: Thu Nov 30 2006(Updated: )
The FTP server in Apple Mac OS X 10.4.8 and earlier, when FTP Access is enabled, will crash when a login failure occurs with a valid user name, which allows remote attackers to cause a denial of service (crash) and enumerate valid usernames.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
macOS Yosemite | <=10.4.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-4403 is considered a denial of service vulnerability.
The best way to mitigate CVE-2006-4403 is to upgrade to a version of macOS later than 10.4.8.
CVE-2006-4403 allows remote attackers to cause a denial of service attack by sending failed login attempts.
CVE-2006-4403 affects Mac OS X 10.4.8 and earlier versions.
Yes, CVE-2006-4403 allows enumeration of valid usernames through the crash induced by failed login attempts.