First published: Thu Jun 16 2005(Updated: )
AFP Server for Mac OS X 10.4.1, when using an ACL enabled volume, does not properly remove an ACL when a file is copied to a directory that does not use ACLs, which will override the POSIX file permissions for that ACL.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple AFP Server |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-1720 is classified as a moderate severity vulnerability.
To address CVE-2005-1720, ensure that all files are copied to directories that support ACLs or update systems to patched versions of the AFP Server.
CVE-2005-1720 affects the AFP Server on Mac OS X 10.4.1 when using ACL enabled volumes.
Exploitation of CVE-2005-1720 may lead to improper permissions being applied to files, potentially exposing sensitive data.
A potential workaround for CVE-2005-1720 is to avoid copying files to non-ACL directories when using ACL enabled volumes.