CVE-2007-5847: Race Condition
Published Dec 19, 2007
·Updated
Race condition in the CFURLWriteDataAndPropertiesToResource API in Core Foundation in Apple Mac OS X 10.4.11 creates files with insecure permissions, which might allow local users to obtain sensitive information.
Affected Software
1 affected component
Apple iOS and macOS=10.4.11
Event History
Dec 19, 2007
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
Who is realistically exposed to this issue?
Systems running the affected Mac OS X 10.4.11 Core Foundation API are exposed when software uses CFURLWriteDataAndPropertiesToResource. Exploitation requires a local user on the system.
2
What access does an attacker need to exploit it?
The vulnerability has local attack vector and requires no authentication. A local user may be able to obtain sensitive information from files created with insecure permissions.
3
What is the expected security impact?
The issue can compromise confidentiality and integrity, while availability is not affected according to the provided vector.