CVE

Id
6878  
CVE No.
CVE-2003-0049  
Status
Candidate  
Description
Apple File Protocol (AFP) in Mac OS X before 10.2.4 allows administrators to log in as other users by using the administrator password.  
Phase
Modified (20071022)  
Votes
ACCEPT(3) Baker, Cole, Green | NOOP(2) Cox, Wall  
Comments
Baker> Realizing they have acknowledged the problem, and provided a fix by allowing the administrator to select whether or not this is allowed, | I am not sure this should really be a vulnerability. If you are the administrator on a system, there are other ways I can become a user | on a system. The fact that you are the administrator (root) you can do almost anything to the system you want, including accessing files | and programs that belong to other users. From a security standpoint, if the system gets "hacked" and the administrator account is compromised, | how big of an issue is it really that the administrator can now access regular user accounts with the administrator password? I am not sure this | should really be a vulnerability. | CHANGE> [Baker changed vote from REVIEWING to ACCEPT]