Overview
A vulnerabilty in the Apple Mac OS X DirectoryService may allow unprivileged users to change the root password.
Description
The Apple Mac OS X DirectoryService contains a vulnerability that may allow unprivileged LDAP users to change the local root password. According to Apple security document 305214 : An implementation flaw in DirectoryService allows an unprivileged LDAP user to change the local root password. The authentication mechanism in DirectoryService has been fixed to address this issue. |
Impact
An unprivileged attacker may be able to change the local root password. |
Solution
Upgrade |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
This vulnerability was reported in Apple Security Update 2007-003.
This document was written by Chris Taschner.
Other Information
CVE IDs: | CVE-2007-0723 |
Severity Metric: | 4.50 |
Date Public: | 2007-03-13 |
Date First Published: | 2007-03-14 |
Date Last Updated: | 2007-03-14 18:05 UTC |
Document Revision: | 19 |