Apple Computer Inc. Information for VU#467828

Mac OS X LDAP plugins transmit user credentials in clear text

Status

Affected

Vendor Statement

Apple:  This is fixed in Security Update 2003-06-09 which is
available as a free download from:
http://docs.info.apple.com/article.html?artnum=120223

Further information, including a workaround for previous
versions, is available in the AppleCare Knowledge Base at
http://docs.info.apple.com/article.html?artnum=107579
"How to Avoid Sending Clear Passwords in a Kerberos
Environment With LDAPv3."

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Vendor References

None

Addendum

The CERT/CC has no additional comments at this time.

If you have feedback, comments, or additional information about this vulnerability, please send us email.