|
|
|
![]() |
Vulnerability Note VU#467828Mac OS X LDAP plugins transmit user credentials in clear textOverviewVersions 10.2 and later of Apple's MacOS X operating system include support for the Lightweight Directory Access Protocol (LDAP). A vulnerability in the way some of these versions of MacOS X handle authentication in certain environments could expose user's passwords in plaintext as they're transmitted across the network.I. DescriptionClient systems using Kerberos login passwords and integration with an LDAP server may inadvertently send the account password over the network to the LDAP server in clear text format. If the "authentication authority" attribute is not set on the LDAP server, the loginwindow application will try to authenticate the account to the configured LDAP server. After trying to authenticate the user with an encrypted password, the loginwindow application falls back to trying a Bind using an AuthenticationChoice of simple on the server. This fallback action causes the account password to be transmitted over the network in clear text.This vulnerability is exposed strictly in an environment where clients are configured to use Kerberos for authentication and LDAP for lookup of other user records. This configuration is not the default for MacOS X, but is commonly recommended and used for environments with a large userbase.
Referenceshttp://docs.info.apple.com/article.html?artnum=107579 Thanks to Patrick M McNeal for reporting this vulnerability. This document was written by Chad R Dougherty.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||