CVE-2011-3216
macOS < 10.7.2 - Unprotected User Data Exposure via Directory Sticky Bit Bypass
Title source: llmDescription
The kernel in Apple Mac OS X before 10.7.2 does not properly implement the sticky bit for directories, which might allow local users to bypass intended permissions and delete files via an unlink system call.
References (3)
Core 3
Core References
Vendor Advisory vendor-advisory
x_refsource_apple
http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.html
Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT5002
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/50085
Scores
EPSS
0.0035
EPSS Percentile
27.3%
Details
CWE
CWE-264
Status
published
Products (50)
apple/mac_os_x
10.0
apple/mac_os_x
10.0.0
apple/mac_os_x
10.0.1
apple/mac_os_x
10.0.2
apple/mac_os_x
10.0.3
apple/mac_os_x
10.0.4
apple/mac_os_x
10.1
apple/mac_os_x
10.1.0
apple/mac_os_x
10.1.1
apple/mac_os_x
10.1.2
... and 40 more
Published
Oct 14, 2011
Tracked Since
Feb 18, 2026