CVE-2009-0014: Low severity Apple iOS and macOS vulnerability
Published Feb 13, 2009
·Updated
Folder Manager in Apple Mac OS X 10.5.6 uses insecure default permissions when recreating a Downloads folder after it has been deleted, which allows local users to bypass intended access restrictions and read the Downloads folder.
Affected Software
2 affected components
Apple iOS and macOS=10.5.6
Apple Mac OS X Server=10.5.6
Remediation
Event History
Feb 13, 2009
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·12:30 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2009-0014?
CVE-2009-0014 has a moderate severity rating due to its impact on local user access control.
2
How does CVE-2009-0014 affect user privacy?
CVE-2009-0014 allows local users to read files in the Downloads folder, potentially compromising sensitive information.
3
How do I fix CVE-2009-0014?
To fix CVE-2009-0014, you should apply the latest security updates provided by Apple for Mac OS X 10.5.6.
4
Who is affected by CVE-2009-0014?
Users of Apple Mac OS X 10.5.6 and Apple Mac OS X Server 10.5.6 are affected by CVE-2009-0014.
5
Can CVE-2009-0014 be exploited remotely?
No, CVE-2009-0014 requires local access, so it cannot be exploited remotely.