PT-2005-2468 · Apple · Macos X

John M. Glenn

·

Published

2005-05-19

·

Updated

2008-09-05

·

CVE-2005-1472

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Apple Mac OS X version 10.4.1
Description: The issue concerns certain system calls in the operating system that do not properly enforce directory permissions. Specifically, directories without the POSIX read bit set but with execute bits set for group or other can be listed by local users, even if they are otherwise restricted.
Recommendations: For Apple Mac OS X version 10.4.1, consider restricting access to sensitive directories by adjusting their permissions to remove execute bits for group or other, until a proper fix is applied.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-1472

Affected Products

Macos X