Vulnonym.com

CVE-2006-4397 - Surrealistic Amplitude

Description

Unchecked error condition in LoginWindow in Apple Mac OS X 10.4 through 10.4.7 prevents Kerberos tickets from being destroyed if a user does not successfully log on to a network account from the login window which might allow later users to gain access to the original user’s Kerberos tickets.

Reference

http://lists.apple.com/archives/security-announce/2006/Sep/msg00002.html http://www.securityfocus.com/bid/20271 http://securitytracker.com/id?1016959 http://secunia.com/advisories/22187 http://www.osvdb.org/29270 http://www.vupen.com/english/advisories/2006/3852