First published: Tue Jul 01 2008(Updated: )
Dock in Apple Mac OS X 10.5 before 10.5.4, when Exposé hot corners is enabled, allows physically proximate attackers to gain access to a locked session in (1) sleep mode or (2) screen saver mode via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
macOS Yosemite | =10.4.3 | |
Apple Mac OS X Server | =10.4.3 | |
Apple Mac OS X Server | =10.5.2 | |
Apple Mac OS X Server | =10.4.10 | |
Apple Mac OS X Server | =10.4.9 | |
Apple Mac OS X Server | =10.4.11 | |
macOS Yosemite | =10.4.1 | |
Apple Mac OS X Server | =10.4.2 | |
Apple Mac OS X Server | =10.4.4 | |
macOS Yosemite | =10.5.1 | |
macOS Yosemite | =10.4.10 | |
Apple Mac OS X Server | =10.4.1 | |
macOS Yosemite | =10.4.9 | |
Apple Mac OS X Server | =10.5.1 | |
macOS Yosemite | =10.4.7 | |
macOS Yosemite | =10.4.4 | |
macOS Yosemite | =10.5.3 | |
Apple Mac OS X Server | =10.5.3 | |
macOS Yosemite | =10.5 | |
Apple Mac OS X Server | =10.4.5 | |
macOS Yosemite | =10.5.2 | |
Apple Mac OS X Server | =10.4.6 | |
Apple Mac OS X Server | =10.4.8 | |
macOS Yosemite | =10.4.6 | |
macOS Yosemite | =10.4.5 | |
macOS Yosemite | =10.4.11 | |
macOS Yosemite | =10.4.8 | |
Apple Mac OS X Server | =10.5 | |
Apple Mac OS X Server | =10.4.7 | |
macOS Yosemite | =10.4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-2314 has a medium severity level, allowing unauthorized access to a locked session.
To fix CVE-2008-2314, upgrade your Apple Mac OS X to version 10.5.4 or later.
CVE-2008-2314 affects Apple Mac OS X versions 10.4.1 to 10.5.3.
CVE-2008-2314 allows physical attackers to bypass session locks through hot corners during sleep or screen saver modes.
A temporary workaround for CVE-2008-2314 is to disable Exposé hot corners until the patch is applied.