PT-2009-5198 · Apple · Macos X

Publicado

2009-11-10

·

Atualizado

2009-11-17

·

CVE-2009-2840

CVSS v2.0

4.9

Média

VetorAV:L/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions Apple Mac OS X version 10.5.8
Description The issue arises from improper handling of temporary files by Spotlight in Apple Mac OS X. This allows local users to overwrite arbitrary files with the privileges of a different user through unspecified vectors.
Recommendations For Apple Mac OS X version 10.5.8, consider restricting access to temporary files created by Spotlight until a proper fix is applied. As a temporary workaround, users can also manually monitor and manage temporary files to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2009-2840

Produtos afetados

Macos X