First published: Tue Nov 10 2009(Updated: )
Race condition in Login Window in Apple Mac OS X 10.6.x before 10.6.2, when at least one account has a blank password, allows attackers to bypass password authentication and obtain login access to an arbitrary account via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS and macOS | =10.6 | |
Apple iOS and macOS | =10.6.1 | |
Apple macOS Server | =10.6 | |
Apple macOS Server | =10.6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-2836 is considered a high severity vulnerability due to its potential for unauthorized access to user accounts.
To fix CVE-2009-2836, users should upgrade their systems to Mac OS X 10.6.2 or later.
CVE-2009-2836 allows attackers to bypass password authentication and gain access to accounts with blank passwords.
CVE-2009-2836 affects Mac OS X versions 10.6 and 10.6.1 as well as their server counterparts.
A system reboot may be necessary after upgrading to a patched version to ensure that security changes take effect.