OSVDB ID: 25590

Title: Apple Mac OS X Keychain Lock Bypass

Info

Disclosure

May 08, 2006

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Unknown

Description

Mac OS X contains a flaw that may allow a malicious application to access Keychain items without first requesting that the Keychain be unlocked. The issue is triggered when the application has obtained a reference to a Keychain item prior to the keychain being locked, which may allow the application to continue to use the item. It is possible that the flaw may allow unauthorized access to login information resulting in a loss of confidentiality.

Classification

Location: Local Access Required
Attack Type: Information Disclosure
Impact: Loss of Confidentiality
Exploit: Exploit Unknown
Disclosure: OSVDB Verified

Solution

Install Apple Security Update 2006-003, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.

Products

Apple Computer, Inc.

Mac OS X

10.3.x
10.4
10.4.1
10.4.2
10.4.3
10.4.4
10.4.5
10.4.6

References

Credit

  • Tobias Hahn -


Direct URL: http://osvdb.org/25590