First published: Tue Mar 30 2010(Updated: )
The Accounts Preferences implementation in Apple Mac OS X 10.6 before 10.6.3, when a network account server is used, does not support Login Window access control that is based solely on group membership, which allows attackers to bypass intended access restrictions by entering login credentials.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Mac OS X Server | =10.6.1 | |
Apple Mac OS X Server | =10.6.2 | |
macOS Yosemite | =10.6.1 | |
Apple Mac OS X Server | =10.6.0 | |
macOS Yosemite | =10.6.0 | |
macOS Yosemite | =10.6.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-0512 is considered to have a medium severity level due to its potential to allow unauthorized access.
To fix CVE-2010-0512, update your Apple macOS to version 10.6.3 or later.
CVE-2010-0512 affects Apple Mac OS X versions 10.6.0, 10.6.1, and 10.6.2, particularly when using network account servers.
CVE-2010-0512 exploits the lack of proper Login Window access control solely based on group membership.
Yes, a patch is available in the form of an update to macOS 10.6.3 or higher.