Description
Directory Services in Apple Mac OS X 10.0.2, 10.0.3, 10.2.8, 10.3.2 and Apple Mac OS X Server 10.2 through 10.3.2 accepts authentication server information from unknown LDAP or NetInfo sources as provided by a malicious DHCP server, which allows remote attackers to gain privileges.
References (5)
Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/13874
Various Sources x_refsource_misc
http://www.carrel.org/dhcp-vuln.html
Vendor Advisory x_refsource_misc
http://docs.info.apple.com/article.html?artnum=32478
Patch, Vendor Advisory x_refsource_confirm
http://docs.info.apple.com/article.html?artnum=61798
Exploit, Vendor Advisory vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/9110
Scores
EPSS
0.0457
EPSS Percentile
90.7%
Details
Status
published
Products (16)
apple/mac_os_x
10.0.2
apple/mac_os_x
10.0.3
apple/mac_os_x
10.2.8
apple/mac_os_x
10.3.2
apple/mac_os_x_server
10.2
apple/mac_os_x_server
10.2.1
apple/mac_os_x_server
10.2.2
apple/mac_os_x_server
10.2.3
apple/mac_os_x_server
10.2.4
apple/mac_os_x_server
10.2.5
... and 6 more
Published
Mar 29, 2004
Tracked Since
Feb 18, 2026