PT-2005-2468 · Apple · Macos X
John M. Glenn
·
Published
2005-05-19
·
Updated
2008-09-05
·
CVE-2005-1472
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Apple Mac OS X version 10.4.1
Description:
The issue concerns certain system calls in the operating system that do not properly enforce directory permissions. Specifically, directories without the POSIX read bit set but with execute bits set for group or other can be listed by local users, even if they are otherwise restricted.
Recommendations:
For Apple Mac OS X version 10.4.1, consider restricting access to sensitive directories by adjusting their permissions to remove execute bits for group or other, until a proper fix is applied.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Macos X