CVE-2004-0922: Medium severity quicktime player vulnerability
AFP Server on Mac OS X 10.3.x to 10.3.5, under certain conditions, does not properly set the guest group ID, which causes AFP to change a write-only AFP Drop Box to be read-write when the Drop Box is on a share that is mounted by a guest, which allows attackers to read the Drop Box.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-0922?
CVE-2004-0922 is classified as a medium severity vulnerability due to its potential for unauthorized access to sensitive data.
How do I fix CVE-2004-0922?
To fix CVE-2004-0922, you should update your Mac OS X to a patched version that adequately addresses this issue.
Who is affected by CVE-2004-0922?
CVE-2004-0922 affects users of Apple Mac OS X versions 10.3.x and QuickTime versions 5.0.2 through 6.5.1.
What type of vulnerability is CVE-2004-0922?
CVE-2004-0922 is a security vulnerability in the Apple Filing Protocol (AFP) server that affects file permissions.
What systems are vulnerable to CVE-2004-0922?
Vulnerable systems include specific versions of Mac OS X 10.3.x and QuickTime applications as indicated in the CVE.