CVE-2014-4447: Low severity Apple OS X Server vulnerability
Published Oct 18, 2014
·Updated
Profile Manager in Apple OS X Server before 4.0 allows local users to discover cleartext passwords by reading a file after a (1) profile setup or (2) profile edit occurs.
Affected Software
1 affected component
Apple OS X Server<=3.1.2
Event History
Oct 18, 2014
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-4447?
CVE-2014-4447 is considered a medium severity vulnerability due to its potential exposure of cleartext passwords.
2
How do I fix CVE-2014-4447?
To mitigate CVE-2014-4447, upgrade to Apple OS X Server version 4.0 or later.
3
What type of vulnerability is CVE-2014-4447?
CVE-2014-4447 is a local information disclosure vulnerability.
4
Who is affected by CVE-2014-4447?
CVE-2014-4447 affects users running Apple OS X Server versions prior to 4.0.
5
What can an attacker gain from CVE-2014-4447?
An attacker with local access can discover cleartext passwords stored in specific files due to CVE-2014-4447.