CVE-2014-1347
Apple iTunes < 11.2.1 - Unprotected User Data Exposure via World-Writable Permissions
Title source: llmDescription
Apple iTunes before 11.2.1 on OS X sets world-writable permissions for /Users and /Users/Shared during reboots, which allows local users to modify files, and consequently obtain access to arbitrary user accounts, via standard filesystem operations.
References (1)
Core 1
Core References
Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT6251
Scores
EPSS
0.0039
EPSS Percentile
31.6%
Details
CWE
CWE-264
Status
published
Products (13)
apple/itunes
11.0
apple/itunes
11.0.1
apple/itunes
11.0.2
apple/itunes
11.0.3
apple/itunes
11.0.4
apple/itunes
11.0.5
apple/itunes
11.1
apple/itunes
11.1.1
apple/itunes
11.1.2
apple/itunes
11.1.3
... and 3 more
Published
May 18, 2014
Tracked Since
Feb 18, 2026