PT-2009-5198 · Apple · Macos X
Published
2009-11-10
·
Updated
2009-11-17
·
CVE-2009-2840
CVSS v2.0
4.9
Medium
| Vector | AV:L/AC:L/Au:N/C:N/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
Apple Mac OS X version 10.5.8
Description
The issue arises from improper handling of temporary files by Spotlight in Apple Mac OS X. This allows local users to overwrite arbitrary files with the privileges of a different user through unspecified vectors.
Recommendations
For Apple Mac OS X version 10.5.8, consider restricting access to temporary files created by Spotlight until a proper fix is applied. As a temporary workaround, users can also manually monitor and manage temporary files to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Macos X