CVE-2006-4399

User interface inconsistency in Workgroup Manager in Apple Mac OS X 10.4 through 10.4.7 appears to allow administrators to change the authentication type from crypt to ShadowHash passwords for accounts in a NetInfo parent, when such an operation is not actually supported, which could result in less secure password management than intended.

Date published : 2006-10-02

http://lists.apple.com/archives/security-announce/2006/Sep/msg00002.html

http://www.securityfocus.com/bid/20271