First published: Tue Sep 16 2008(Updated: )
Remote Management and Screen Sharing in Apple Mac OS X 10.5 through 10.5.4, when used to set a password for a VNC viewer, displays additional input characters beyond the maximum password length, which might make it easier for attackers to guess passwords that the user believed were longer.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Mac OS X Server | =10.5.2 | |
macOS Yosemite | =10.5.1 | |
Apple Mac OS X Server | =10.5.1 | |
macOS Yosemite | =10.5.3 | |
Apple Mac OS X Server | =10.5.3 | |
macOS Yosemite | =10.5 | |
Apple Mac OS X Server | =10.5.4 | |
macOS Yosemite | =10.5.2 | |
Apple Mac OS X Server | =10.5 | |
macOS Yosemite | =10.5.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-3617 is considered a medium severity vulnerability as it can lead to easier password guessing.
To fix CVE-2008-3617, update your Apple Mac OS X to a version later than 10.5.4.
CVE-2008-3617 affects macOS versions 10.5, 10.5.1, 10.5.2, 10.5.3, and 10.5.4.
CVE-2008-3617 can compromise password security by revealing additional input characters that may allow for easier password cracking.
Yes, enabling Remote Management with a password using affected versions of macOS can expose the vulnerability of CVE-2008-3617.