CVE-2016-4745

CVE-2016-4745

The Kerberos 5 (aka krb5) PAM module in Apple OS X before 10.12 does not use constant-time operations for determining username validity, which makes it easier for remote attackers to enumerate user accounts via a timing side-channel attack.

Source: CVE-2016-4745

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다