CVE-2010-0545
Apple Mac OS X 10.5.8 and 10.6 < 10.6.4 - Unprotected User Data Exposure via Finder Apply to Enclosed Items
Title source: llmDescription
The Finder in DesktopServices in Apple Mac OS X 10.5.8, and 10.6 before 10.6.4, does not set the expected file ownerships during an "Apply to enclosed items" action, which allows local users to bypass intended access restrictions via normal filesystem operations.
References (6)
Core 6
Core References
Vendor Advisory vendor-advisory
x_refsource_apple
http://lists.apple.com/archives/security-announce/2010//Jun/msg00001.html
Patch, Vendor Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2010/1481
Patch vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/40871
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://securitytracker.com/id?1024103
Patch, Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT4188
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/40220
Scores
EPSS
0.0030
EPSS Percentile
22.4%
Details
CWE
CWE-264
Status
published
Products (10)
apple/mac_os_x
10.5.8
apple/mac_os_x
10.6.0
apple/mac_os_x
10.6.1
apple/mac_os_x
10.6.2
apple/mac_os_x
10.6.3
apple/mac_os_x_server
10.5.8
apple/mac_os_x_server
10.6.0
apple/mac_os_x_server
10.6.1
apple/mac_os_x_server
10.6.2
apple/mac_os_x_server
10.6.3
Published
Jun 17, 2010
Tracked Since
Feb 18, 2026