Apple Computer Inc. Affected

Notified:  May 19, 2003 Updated: June 23, 2003



Vendor Statement

Apple: This is fixed in Security Update 2003-06-09 which is available as a free download from: Further information, including a workaround for previous versions, is available in the AppleCare Knowledge Base at "How to Avoid Sending Clear Passwords in a Kerberos Environment With LDAPv3."

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.


The CERT/CC has no additional comments at this time.