First published: Thu May 19 2005(Updated: )
Certain system calls in Apple Mac OS X 10.4.1 do not properly enforce the permissions of certain directories without the POSIX read bit set, but with the execute bits set for group or other, which allows local users to list files in otherwise restricted directories.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
macOS Yosemite | =10.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-1472 is rated as a moderate severity vulnerability due to improper permission enforcement.
To fix CVE-2005-1472, ensure that proper permissions are set on restricted directories in Mac OS X 10.4.1.
The consequences of CVE-2005-1472 include unauthorized access to sensitive files by local users.
CVE-2005-1472 specifically affects Apple Mac OS X version 10.4.1.
Yes, local users can exploit CVE-2005-1472 to list files in restricted directories.