First published: Tue Apr 27 2010(Updated: )
The hfs implementation in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 supports hard links to directories and does not prevent certain deeply nested directory structures, which allows local users to cause a denial of service (filesystem corruption) via a crafted application that calls the mkdir and link functions, related to the fsck_hfs program in the diskdev_cmds component.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS and macOS | =10.5.8 | |
Apple iOS and macOS | =10.6.3 | |
Apple iOS and macOS | =10.6.1 | |
Apple iOS and macOS | =10.6.0 | |
Apple iOS and macOS | =10.6.2 | |
Apple iOS and macOS | =10.6.4 | |
=10.5.8 | ||
=10.6.0 | ||
=10.6.1 | ||
=10.6.2 | ||
=10.6.3 | ||
=10.6.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-0105 is considered a moderate severity vulnerability due to its potential to cause filesystem corruption.
To fix CVE-2010-0105, users should update their macOS to version 10.6.5 or later.
CVE-2010-0105 affects Apple Mac OS X versions 10.5.8, 10.6.0 through 10.6.4.
CVE-2010-0105 cannot be exploited remotely as it requires local access to the system.
CVE-2010-0105 poses a denial of service threat that can lead to filesystem corruption.