Apple Mac OS X contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered when Mobile Accounts saves password hashes during the creation of a new account. This may allow a remote attacker to gain access to the hash information when the mobile account was used as an external account. The password hash may then be used to help determine what the password itself is.
Classification
Location:
Remote / Network Access
Attack Type:
Information Disclosure
Impact:
Loss of Confidentiality
Solution:
Patch / RCS,
Upgrade
Exploit:
Exploit Private
Disclosure:
Vendor Verified,
Coordinated Disclosure
Solution
Upgrade to version 10.8.2 or 10.7.5 or higher, as they have been reported to fix this vulnerability. In addition, Apple has released a patch for some older versions.