CVE-2008-4212
Unspecified vulnerability in rlogind in the rlogin component in Mac OS X 10.4.11 and 10.5.5 applies hosts.equiv entries to root despite what is stated in documentation, which might allow remote attackers to bypass intended access restrictions.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.59%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Unspecified vulnerability in rlogind in the rlogin component in Mac OS X 10.4.11 and 10.5.5 applies hosts.equiv entries to root despite what is stated in documentation, which might allow remote attackers to bypass intended access restrictions.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 2.59% probability · 84th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-16
- Affected
- apple/mac os x · apple/mac os x server
- Source
- cve@mitre.org
References
- http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.htmlVendor Advisory
- http://secunia.com/advisories/32222Vendor Advisory
- http://support.apple.com/kb/HT3216
- http://www.securityfocus.com/bid/31681Patch
- http://www.securityfocus.com/bid/31708
- http://www.securitytracker.com/id?1021028
- http://www.vupen.com/english/advisories/2008/2780
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45785
- http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.htmlVendor Advisory
- http://secunia.com/advisories/32222Vendor Advisory
- http://support.apple.com/kb/HT3216
- http://www.securityfocus.com/bid/31681Patch
- http://www.securityfocus.com/bid/31708
- http://www.securitytracker.com/id?1021028
- http://www.vupen.com/english/advisories/2008/2780
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45785
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.