First published: Fri May 11 2012(Updated: )
Login Window in Apple Mac OS X 10.7.3, when Legacy File Vault or networked home directories are enabled, does not properly restrict what is written to the system log for network logins, which allows local users to obtain sensitive information by reading the log.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
macOS Yosemite | =10.7.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-0652 has a severity rating of medium due to its potential for local information disclosure.
To fix CVE-2012-0652, Apple recommends updating to a version of macOS that addresses the vulnerability.
CVE-2012-0652 affects Apple Mac OS X version 10.7.3 when Legacy File Vault or networked home directories are enabled.
CVE-2012-0652 allows local users to read sensitive login information from system logs.
If your system is running Mac OS X 10.7.3 and has not been updated, it may still be vulnerable to risks associated with CVE-2012-0652.