CVE-2008-0993: Infoleak
Published Mar 18, 2008
·Updated
Podcast Capture in Podcast Producer for Apple Mac OS X 10.5.2 invokes a subtask with passwords in command line arguments, which allows local users to read the passwords via process listings.
Affected Software
3 affected components
Apple iOS and macOS=10.5.2
Apple Mac OS X Server=10.5.2
Apple Podcast Producer
Remediation
Event History
Mar 18, 2008
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Data Sourced
11:44 PM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2008-0993?
CVE-2008-0993 is classified as a moderate severity vulnerability affecting Apple Mac OS X 10.5.2.
2
How do I fix CVE-2008-0993?
To fix CVE-2008-0993, it is recommended to upgrade to a later version of macOS or Podcast Producer that addresses this issue.
3
Who is affected by CVE-2008-0993?
CVE-2008-0993 affects local users of Mac OS X 10.5.2 and users of the Apple Podcast Producer application.
4
What type of attack does CVE-2008-0993 enable?
CVE-2008-0993 allows local users to read sensitive passwords through process listings due to insecure command line arguments.
5
What software components are involved in CVE-2008-0993?
CVE-2008-0993 involves the Podcast Capture feature in the Apple Podcast Producer application on macOS.