Medium severity5.3NVD Advisory· Published Sep 25, 2016· Updated May 6, 2026
CVE-2016-4745
CVE-2016-4745
Description
The Kerberos 5 (aka krb5) PAM module in Apple OS X before 10.12 does not use constant-time operations for determining username validity, which makes it easier for remote attackers to enumerate user accounts via a timing side-channel attack.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- lists.apple.com/archives/security-announce/2016/Sep/msg00006.htmlnvdMailing ListVendor Advisory
- support.apple.com/HT207170nvdVendor Advisory
- www.securityfocus.com/bid/93055nvd
- www.securitytracker.com/id/1036858nvd
News mentions
0No linked articles in our index yet.