|
|
|
![]() |
Vulnerability Note VU#371648Apple Mac OS X ftpd may allow arbitrary users to determine account name validityOverviewApple Mac OS X ftpd may allow arbitrary users to determine account name validity. This vulnerability may reveal protected information or allow an attacker to cause a denial-of-service condition.I. DescriptionAccording to Apple Security Update 2006-007:When attempting to authenticate a valid user, the FTP server may crash during a failed login attempt. The crash does not occur when attempting to authenticate unknown users. II. ImpactA remote, unauthenticated attacker may be able to determine protected information or cause a denial-of-service condition.III. SolutionApply Apple UpdatesThis issue is addressed by Apple Security Update 2006-007.
References
This issue was reported in Apple Security Update 2006-007. Apple credits Benjamin Williams of the University of Canterbury for reporting this issue. This document was written by Chris Taschner.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||