Overview
A vulnerabilty in the Apple Mac OS X DirectoryService may allow unprivileged users to change the root password.
Description
The Apple Mac OS X DirectoryService contains a vulnerability that may allow unprivileged LDAP users to change the local root password. According to Apple security document 305214 : An implementation flaw in DirectoryService allows an unprivileged LDAP user to change the local root password. The authentication mechanism in DirectoryService has been fixed to address this issue. |
Impact
An unprivileged attacker may be able to change the local root password. |
Solution
Upgrade |
Vendor Information
CVSS Metrics
| Group | Score | Vector |
|---|---|---|
| Base | ||
| Temporal | ||
| Environmental |
References
Acknowledgements
This vulnerability was reported in Apple Security Update 2007-003.
This document was written by Chris Taschner.
Other Information
| CVE IDs: | CVE-2007-0723 |
| Severity Metric: | 4.50 |
| Date Public: | 2007-03-13 |
| Date First Published: | 2007-03-14 |
| Date Last Updated: | 2007-03-14 18:05 UTC |
| Document Revision: | 19 |