CVE-2014-1347

Apple iTunes < 11.2.1 - Unprotected User Data Exposure via World-Writable Permissions

Title source: llm
STIX 2.1

Description

Apple iTunes before 11.2.1 on OS X sets world-writable permissions for /Users and /Users/Shared during reboots, which allows local users to modify files, and consequently obtain access to arbitrary user accounts, via standard filesystem operations.

References (1)

Core 1
Core References
Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT6251

Scores

EPSS 0.0039
EPSS Percentile 31.6%

Details

CWE
CWE-264
Status published
Products (13)
apple/itunes 11.0
apple/itunes 11.0.1
apple/itunes 11.0.2
apple/itunes 11.0.3
apple/itunes 11.0.4
apple/itunes 11.0.5
apple/itunes 11.1
apple/itunes 11.1.1
apple/itunes 11.1.2
apple/itunes 11.1.3
... and 3 more
Published May 18, 2014
Tracked Since Feb 18, 2026