First published: Wed Aug 02 2006(Updated: )
AFP Server in Apple Mac OS X 10.3.9 and 10.4.7 stores reconnect keys in a world-readable file, which allows local users to obtain the keys and access files and folders of other users.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
macOS Yosemite | =10.4.7 | |
Apple Mac OS X Server | =10.3.9 | |
macOS Yosemite | =10.3.9 | |
Apple Mac OS X Server | =10.4.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-3495 has a high severity rating due to the potential for local users to access sensitive data from other users' files and folders.
To fix CVE-2006-3495, ensure that the reconnect keys are stored in a secure location with appropriate permissions to restrict access.
CVE-2006-3495 affects Apple Mac OS X versions 10.3.9 and 10.4.7.
Local users on systems running Apple Mac OS X 10.3.9 and 10.4.7 are vulnerable to CVE-2006-3495 due to improperly secured files.
CVE-2006-3495 is a local file access vulnerability that exposes sensitive information due to poor file permissions.