CVE-2010-0537: Low severity Apple Mac OS X Server vulnerability
Published Mar 30, 2010
·Updated
DesktopServices in Apple Mac OS X 10.6 before 10.6.3 does not properly resolve pathnames in certain circumstances involving an application's save panel, which allows user-assisted remote attackers to trigger unintended remote file copying via a crafted share name.
Affected Software
6 affected components
Apple Mac OS X Server=10.6.1
Apple Mac OS X Server=10.6.2
Apple iOS and macOS=10.6.1
Apple Mac OS X Server=10.6.0
Apple iOS and macOS=10.6.0
Apple iOS and macOS=10.6.2
Remediation
Patch Available
Event History
Mar 30, 2010
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Data Sourced
via NVD·06:30 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2010-0537?
CVE-2010-0537 has been classified with a moderate severity level due to potential user-assisted exploitation.
2
How do I fix CVE-2010-0537?
To fix CVE-2010-0537, users should update their Mac OS X to version 10.6.3 or later.
3
What systems are affected by CVE-2010-0537?
CVE-2010-0537 affects Apple Mac OS X versions 10.6.0, 10.6.1, and 10.6.2.
4
What type of attack is related to CVE-2010-0537?
CVE-2010-0537 allows user-assisted remote attackers to trigger unintended remote file copying.
5
What is a user-assisted attack in the context of CVE-2010-0537?
A user-assisted attack in the context of CVE-2010-0537 occurs when a user unknowingly interacts with a crafted share name.