Apple Macintosh OS X .DS_Store Directory Listing Disclosure Vulnerability
BID:3324
Info
Apple Macintosh OS X .DS_Store Directory Listing Disclosure Vulnerability
| Bugtraq ID: | 3324 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 11 2001 12:00AM |
| Updated: | Sep 11 2001 12:00AM |
| Credit: | Reported to "MacInTouch Reader Reports" by Jacques Distler on August 8, 2001. Submitted to bugtraq by Eric Bennett <[email protected]> on August 10, 2001. |
| Vulnerable: |
Apple Mac OS X 10.0.4 Apple Mac OS X 10.0.3 Apple Mac OS X 10.0.2 Apple Mac OS X 10.0.1 Apple Mac OS X 10.0 |
| Not Vulnerable: |
Apple Mac OS X 10.1 |
Discussion
Apple Macintosh OS X .DS_Store Directory Listing Disclosure Vulnerability
A vulnerability has been found in certain configurations of Macintosh OS X.
A remote attacker may read obtain web directory content information by submitting a URL to the vulnerable host's web service of the following form:
http://www.example.com/target_directory/.DS_store.
This information could provide an attacker with sensitive information including system configuration, installed applications, etc. Properly exploited, this information could allow an attacker to further compromise the security of the host.
A vulnerability has been found in certain configurations of Macintosh OS X.
A remote attacker may read obtain web directory content information by submitting a URL to the vulnerable host's web service of the following form:
http://www.example.com/target_directory/.DS_store.
This information could provide an attacker with sensitive information including system configuration, installed applications, etc. Properly exploited, this information could allow an attacker to further compromise the security of the host.
Exploit / POC
Apple Macintosh OS X .DS_Store Directory Listing Disclosure Vulnerability
See discussion.
See discussion.
Solution / Fix
Apple Macintosh OS X .DS_Store Directory Listing Disclosure Vulnerability
Solution:
Apple has released MacOS X 10.1 which is not vulnerable to this issue.
Solution:
Apple has released MacOS X 10.1 which is not vulnerable to this issue.
References
Apple Macintosh OS X .DS_Store Directory Listing Disclosure Vulnerability
References:
References:
- More security problems in Apache on Mac OS X (MacInTouch User Reports)
- Security Updates (Apple)