CVE-2012-0652

medium

Description

Login Window in Apple Mac OS X 10.7.3, when Legacy File Vault or networked home directories are enabled, does not properly restrict what is written to the system log for network logins, which allows local users to obtain sensitive information by reading the log.

References

http://www.securitytracker.com/id?1027024

http://www.securityfocus.com/bid/53457

http://www.securityfocus.com/bid/53445

http://support.apple.com/kb/HT5501

http://support.apple.com/kb/HT5281

http://lists.apple.com/archives/security-announce/2012/Sep/msg00004.html

http://lists.apple.com/archives/security-announce/2012/May/msg00001.html

Details

Source: Mitre, NVD

Published: 2012-05-11

Updated: 2017-12-05

Risk Information

CVSS v2

Base Score: 4.9

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:N/A:N

Severity: Medium

CVSS v3

Base Score: 5.5

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Severity: Medium