First published: Fri Feb 13 2009(Updated: )
Folder Manager in Apple Mac OS X 10.5.6 uses insecure default permissions when recreating a Downloads folder after it has been deleted, which allows local users to bypass intended access restrictions and read the Downloads folder.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
macOS Yosemite | =10.5.6 | |
Apple Mac OS X Server | =10.5.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-0014 has a moderate severity rating due to its impact on local user access control.
CVE-2009-0014 allows local users to read files in the Downloads folder, potentially compromising sensitive information.
To fix CVE-2009-0014, you should apply the latest security updates provided by Apple for Mac OS X 10.5.6.
Users of Apple Mac OS X 10.5.6 and Apple Mac OS X Server 10.5.6 are affected by CVE-2009-0014.
No, CVE-2009-0014 requires local access, so it cannot be exploited remotely.