VulnerabilityModified
CVE-2012-0652
Login Window in Apple Mac OS X 10.7.3, when Legacy File Vault or networked home directories are enabled, does not properly restrict what is written to the system log for network logins, which allows local users to obtain sensitive information by reading…
MEDIUM 4.9EPSS 0.33%
Does this matter?
Lower severity and a low EPSS score (0.33%). Track it; it rarely justifies an emergency change on its own.
Description
Login Window in Apple Mac OS X 10.7.3, when Legacy File Vault or networked home directories are enabled, does not properly restrict what is written to the system log for network logins, which allows local users to obtain sensitive information by reading the log.
- CVSS 2.0
- 4.9 MEDIUMAV:L/AC:L/Au:N/C:C/I:N/A:N
- EPSS
- 0.33% probability · 27th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- apple/mac os x
- Source
- product-security@apple.com
References
- http://lists.apple.com/archives/security-announce/2012/May/msg00001.htmlVendor Advisory
- http://lists.apple.com/archives/security-announce/2012/Sep/msg00004.html
- http://support.apple.com/kb/HT5281Vendor Advisory
- http://support.apple.com/kb/HT5501
- http://www.securityfocus.com/bid/53445
- http://www.securityfocus.com/bid/53457
- http://www.securitytracker.com/id?1027024
- http://lists.apple.com/archives/security-announce/2012/May/msg00001.htmlVendor Advisory
- http://lists.apple.com/archives/security-announce/2012/Sep/msg00004.html
- http://support.apple.com/kb/HT5281Vendor Advisory
- http://support.apple.com/kb/HT5501
- http://www.securityfocus.com/bid/53445
- http://www.securityfocus.com/bid/53457
- http://www.securitytracker.com/id?1027024
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.