MobileMe in Apple Mac OS X 10.5 before 10.5.8 does not properly delete credentials upon signout from the preference pane, which makes it easier for attackers to hijack a MobileMe session via unspecified vectors, related to a "logic issue."
                
            References
                    | Link | Resource | 
|---|---|
| http://lists.apple.com/archives/security-announce/2009/Aug/msg00001.html | Patch Vendor Advisory | 
| http://osvdb.org/56839 | |
| http://secunia.com/advisories/36096 | Vendor Advisory | 
| http://support.apple.com/kb/HT3757 | Patch Vendor Advisory | 
| http://www.securityfocus.com/bid/35954 | Patch | 
| http://www.us-cert.gov/cas/techalerts/TA09-218A.html | US Government Resource | 
| http://www.vupen.com/english/advisories/2009/2172 | Patch Vendor Advisory | 
| https://exchange.xforce.ibmcloud.com/vulnerabilities/52432 | |
| http://lists.apple.com/archives/security-announce/2009/Aug/msg00001.html | Patch Vendor Advisory | 
| http://osvdb.org/56839 | |
| http://secunia.com/advisories/36096 | Vendor Advisory | 
| http://support.apple.com/kb/HT3757 | Patch Vendor Advisory | 
| http://www.securityfocus.com/bid/35954 | Patch | 
| http://www.us-cert.gov/cas/techalerts/TA09-218A.html | US Government Resource | 
| http://www.vupen.com/english/advisories/2009/2172 | Patch Vendor Advisory | 
| https://exchange.xforce.ibmcloud.com/vulnerabilities/52432 | 
Configurations
                    Configuration 1 (hide)
| 
 | 
History
                    21 Nov 2024, 01:04
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () http://lists.apple.com/archives/security-announce/2009/Aug/msg00001.html - Patch, Vendor Advisory | |
| References | () http://osvdb.org/56839 - | |
| References | () http://secunia.com/advisories/36096 - Vendor Advisory | |
| References | () http://support.apple.com/kb/HT3757 - Patch, Vendor Advisory | |
| References | () http://www.securityfocus.com/bid/35954 - Patch | |
| References | () http://www.us-cert.gov/cas/techalerts/TA09-218A.html - US Government Resource | |
| References | () http://www.vupen.com/english/advisories/2009/2172 - Patch, Vendor Advisory | |
| References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/52432 - | 
Information
                Published : 2009-08-06 16:30
Updated : 2025-04-09 00:30
NVD link : CVE-2009-2192
Mitre link : CVE-2009-2192
CVE.ORG link : CVE-2009-2192
JSON object : View
Products Affected
                apple
- mac_os_x
- mac_os_x_server
CWE
                
                    
                        
                        CWE-255
                        
            Credentials Management Errors
