PT-2009-5198 · Apple · Macos X

Published

2009-11-10

·

Updated

2009-11-17

·

CVE-2009-2840

CVSS v2.0

4.9

Medium

VectorAV:L/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions Apple Mac OS X version 10.5.8
Description The issue arises from improper handling of temporary files by Spotlight in Apple Mac OS X. This allows local users to overwrite arbitrary files with the privileges of a different user through unspecified vectors.
Recommendations For Apple Mac OS X version 10.5.8, consider restricting access to temporary files created by Spotlight until a proper fix is applied. As a temporary workaround, users can also manually monitor and manage temporary files to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2009-2840

Affected Products

Macos X