First published: Tue Sep 16 2008(Updated: )
Login Window in Apple Mac OS X 10.4.11 does not clear the current password when a user makes a password-change attempt that is denied by policy, which allows opportunistic, physically proximate attackers to bypass authentication and change this user's password by later entering an acceptable new password on the same login screen.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Mac OS X Server | =10.4.11 | |
macOS Yosemite | =10.4.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-3611 is considered a high-severity vulnerability as it allows local attackers to bypass authentication.
To fix CVE-2008-3611, it is recommended to upgrade to a version of macOS that is not affected by this vulnerability.
Users of Apple Mac OS X 10.4.11 and Apple Mac OS X Server 10.4.11 are affected by CVE-2008-3611.
CVE-2008-3611 is an authentication bypass vulnerability related to password change attempts.
No, CVE-2008-3611 requires physical access to the device for exploitation.