CVE-2011-3216

macOS < 10.7.2 - Unprotected User Data Exposure via Directory Sticky Bit Bypass

Title source: llm
STIX 2.1

Description

The kernel in Apple Mac OS X before 10.7.2 does not properly implement the sticky bit for directories, which might allow local users to bypass intended permissions and delete files via an unlink system call.

References (3)

Core 3
Core References
Vendor Advisory vendor-advisory x_refsource_apple
http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.html
Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT5002
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/50085

Scores

EPSS 0.0035
EPSS Percentile 27.3%

Details

CWE
CWE-264
Status published
Products (50)
apple/mac_os_x 10.0
apple/mac_os_x 10.0.0
apple/mac_os_x 10.0.1
apple/mac_os_x 10.0.2
apple/mac_os_x 10.0.3
apple/mac_os_x 10.0.4
apple/mac_os_x 10.1
apple/mac_os_x 10.1.0
apple/mac_os_x 10.1.1
apple/mac_os_x 10.1.2
... and 40 more
Published Oct 14, 2011
Tracked Since Feb 18, 2026