CVE-2010-0545

Apple Mac OS X 10.5.8 and 10.6 < 10.6.4 - Unprotected User Data Exposure via Finder Apply to Enclosed Items

Title source: llm
STIX 2.1

Description

The Finder in DesktopServices in Apple Mac OS X 10.5.8, and 10.6 before 10.6.4, does not set the expected file ownerships during an "Apply to enclosed items" action, which allows local users to bypass intended access restrictions via normal filesystem operations.

References (6)

Core 6
Core References
Vendor Advisory vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2010//Jun/msg00001.html
Patch, Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2010/1481
Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/40871
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1024103
Patch, Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT4188
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/40220

Scores

EPSS 0.0030
EPSS Percentile 22.4%

Details

CWE
CWE-264
Status published
Products (10)
apple/mac_os_x 10.5.8
apple/mac_os_x 10.6.0
apple/mac_os_x 10.6.1
apple/mac_os_x 10.6.2
apple/mac_os_x 10.6.3
apple/mac_os_x_server 10.5.8
apple/mac_os_x_server 10.6.0
apple/mac_os_x_server 10.6.1
apple/mac_os_x_server 10.6.2
apple/mac_os_x_server 10.6.3
Published Jun 17, 2010
Tracked Since Feb 18, 2026