CVE-2004-0622
Apple Mac OS X 10.3.4, 10.4, 10.5, and possibly other versions does not properly clear memory for login (aka Loginwindow.app), Keychain, or FileVault passwords, which could allow the root user or an attacker with physical access to obtain sensitive…
Does this matter?
Lower severity and a low EPSS score (0.36%). Track it; it rarely justifies an emergency change on its own.
Description
Apple Mac OS X 10.3.4, 10.4, 10.5, and possibly other versions does not properly clear memory for login (aka Loginwindow.app), Keychain, or FileVault passwords, which could allow the root user or an attacker with physical access to obtain sensitive information by reading memory.
- CVSS 2.0
- 2.1 LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 0.36% probability · 29th percentile
- CISA KEV
- Not listed
- Affected
- apple/mac os x
- Source
- cve@mitre.org
References
- http://citp.princeton.edu/pub/coldboot.pdf
- http://marc.info/?l=bugtraq&m=108819559925981&w=2
- http://www.securityfocus.com/archive/1/488930/100/100/threaded
- http://www.securityfocus.com/archive/1/488948/100/100/threaded
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16557
- http://citp.princeton.edu/pub/coldboot.pdf
- http://marc.info/?l=bugtraq&m=108819559925981&w=2
- http://www.securityfocus.com/archive/1/488930/100/100/threaded
- http://www.securityfocus.com/archive/1/488948/100/100/threaded
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16557
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.