CVE-2011-0197: Infoleak
App Store in Apple Mac OS X before 10.6.8 creates a log entry containing a user's AppleID password, which might allow local users to obtain sensitive information by reading a log file, as demonstrated by a log file that has non-default permissions.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-0197?
CVE-2011-0197 has a medium severity rating due to the potential exposure of sensitive user credentials.
How do I fix CVE-2011-0197?
To mitigate CVE-2011-0197, it is recommended to update your Mac OS X to version 10.6.8 or later.
What does CVE-2011-0197 affect?
CVE-2011-0197 affects Apple Mac OS X versions before 10.6.8, including various versions of Mac OS X and Mac OS X Server.
What information is exposed in CVE-2011-0197?
CVE-2011-0197 can expose a user's AppleID password through log entries that may be read by local users.
Who is at risk from CVE-2011-0197?
Local users on affected systems are at risk of obtaining sensitive information from log files containing AppleID passwords.