CVE-2010-0545
Summary
| CVE | CVE-2010-0545 |
|---|---|
| State | PUBLISHED |
| Assigner | apple |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-06-17 16:30:01 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | The Finder in DesktopServices in Apple Mac OS X 10.5.8, and 10.6 before 10.6.4, does not set the expected file ownerships during an "Apply to enclosed items" action, which allows local users to bypass intended access restrictions via normal filesystem operations. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:L/AC:M/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Apple | Mac Os X | 10.5.8 | All | All | All |
| Operating System | Apple | Mac Os X | 10.6.0 | All | All | All |
| Operating System | Apple | Mac Os X | 10.6.1 | All | All | All |
| Operating System | Apple | Mac Os X | 10.6.2 | All | All | All |
| Operating System | Apple | Mac Os X | 10.6.3 | All | All | All |
| Operating System | Apple | Mac Os X Server | 10.5.8 | All | All | All |
| Operating System | Apple | Mac Os X Server | 10.6.0 | All | All | All |
| Operating System | Apple | Mac Os X Server | 10.6.1 | All | All | All |
| Operating System | Apple | Mac Os X Server | 10.6.2 | All | All | All |
| Operating System | Apple | Mac Os X Server | 10.6.3 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Apple Mac OS X Security Update Fixes Multiple Vulnerabilities - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| SecurityTracker.com Archives - Mac OS X Multiple Flaws Let Remote Users Execute Arbitrary Code, Deny Service, and Upload/Access Files and Local Users Gain Elevated Privileges | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Patch, Vendor Advisory |
| About the security content of Security Update 2010-004 / Mac OS X v10.6.4 | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | Patch, Vendor Advisory |
| RETIRED: Apple Mac OS X Prior to 10.6.4 Multiple Security Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Patch |
| APPLE-SA-2010-06-15-1 Security Update 2010-004 / Mac OS X v10.6.4 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.