First published: Tue Sep 16 2008(Updated: )
Race condition in Login Window in Apple Mac OS X 10.5 through 10.5.4, when a blank-password account is enabled, allows attackers to bypass password authentication and login to any account via multiple attempts to login to the blank-password account, followed by selection of an arbitrary account from the user list.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Mac OS X Server | =10.5.2 | |
macOS Yosemite | =10.5.1 | |
Apple Mac OS X Server | =10.5.1 | |
macOS Yosemite | =10.5.3 | |
Apple Mac OS X Server | =10.5.3 | |
macOS Yosemite | =10.5 | |
Apple Mac OS X Server | =10.5.4 | |
macOS Yosemite | =10.5.2 | |
Apple Mac OS X Server | =10.5 | |
macOS Yosemite | =10.5.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-3610 is classified as a high severity vulnerability due to its potential to allow attackers to bypass password authentication.
To resolve CVE-2008-3610, ensure that all accounts do not have blank passwords and update to a non-vulnerable version of Apple Mac OS X.
CVE-2008-3610 affects Apple Mac OS X versions 10.5 through 10.5.4.
CVE-2008-3610 is a race condition vulnerability occurring in the Login Window of affected Mac OS X versions.
Yes, CVE-2008-3610 affects both Apple Mac OS X Server and standard macOS installations.