Mac OS X contains a flaw that may allow a malicious application to access Keychain items without first requesting that the Keychain be unlocked. The issue is triggered when the application has obtained a reference to a Keychain item prior to the keychain being locked, which may allow the application to continue to use the item. It is possible that the flaw may allow unauthorized access to login information resulting in a loss of confidentiality.
Classification
Location:
Local Access Required
Attack Type:
Information Disclosure
Impact:
Loss of Confidentiality
Exploit:
Exploit Unknown
Disclosure:
OSVDB Verified
Solution
Install Apple Security Update 2006-003, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.