Apple Mac OS X Local Filename Information Disclosure Vulnerability
BID:13695
Info
Apple Mac OS X Local Filename Information Disclosure Vulnerability
| Bugtraq ID: | 13695 |
| Class: | Access Validation Error |
| CVE: |
CVE-2005-1472 |
| Remote: | No |
| Local: | Yes |
| Published: | May 20 2005 12:00AM |
| Updated: | Jul 12 2009 02:56PM |
| Credit: | John M. Glenn of San Francisco is credited with the discovery of this issue. |
| Vulnerable: |
Apple Mac OS X Server 10.4 Apple Mac OS X 10.4 |
| Not Vulnerable: |
Apple Mac OS X Server 10.4.1 Apple Mac OS X 10.4.1 |
Discussion
Apple Mac OS X Local Filename Information Disclosure Vulnerability
Apple Mac OS X is susceptible to a local information disclosure vulnerability. This is due to a failure of the operating system to properly implement POSIX permissions checking in certain circumstances.
This vulnerability allows local attackers to retrieve normally forbidden names contained in directories. This scenario is commonly used to obscure access to public directories (such as '~/Public/Drop Box') for security reasons, as users are required to have knowledge about already existing files contained in these directories to be able to access them.
Apple Mac OS X is susceptible to a local information disclosure vulnerability. This is due to a failure of the operating system to properly implement POSIX permissions checking in certain circumstances.
This vulnerability allows local attackers to retrieve normally forbidden names contained in directories. This scenario is commonly used to obscure access to public directories (such as '~/Public/Drop Box') for security reasons, as users are required to have knowledge about already existing files contained in these directories to be able to access them.
Exploit / POC
Apple Mac OS X Local Filename Information Disclosure Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Apple Mac OS X Local Filename Information Disclosure Vulnerability
Solution:
Apple has released advisory APPLE-SA-2005-05-19, along with fixes to address this and other issues. Please see the referenced advisory for more information.
Apple Mac OS X Server 10.4
Apple Mac OS X 10.4
Solution:
Apple has released advisory APPLE-SA-2005-05-19, along with fixes to address this and other issues. Please see the referenced advisory for more information.
Apple Mac OS X Server 10.4
-
Apple MacOSXSvrUpdate10.4.1.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=06210&plat form=osx&method=sa/MacOSXSvrUpdate10.4.1.dmg
Apple Mac OS X 10.4
-
Apple MacOSXUpdate10.4.1.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=06142&plat form=osx&method=sa/MacOSXUpdate10.4.1.dmg
References
Apple Mac OS X Local Filename Information Disclosure Vulnerability
References:
References:
- Apple Security Updates (Apple)
- Mac OS X Homepage (Apple)