Apple Computer Inc. Information for VU#467828

Mac OS X LDAP plugins transmit user credentials in clear text



Vendor Statement

Apple:  This is fixed in Security Update 2003-06-09 which is
available as a free download from:

Further information, including a workaround for previous
versions, is available in the AppleCare Knowledge Base at
"How to Avoid Sending Clear Passwords in a Kerberos
Environment With LDAPv3."

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Vendor References



The CERT/CC has no additional comments at this time.

If you have feedback, comments, or additional information about this vulnerability, please send us email.