First published: Thu Jun 17 2010(Updated: )
Folder Manager in Apple Mac OS X 10.5.8, and 10.6 before 10.6.4, allows local users to delete arbitrary folders via a symlink attack in conjunction with an unmount operation on a crafted volume, related to the Cleanup At Startup folder.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
macOS Yosemite | =10.5.8 | |
Apple Mac OS X Server | =10.5.8 | |
Apple Mac OS X Server | =10.6.3 | |
macOS Yosemite | =10.6.3 | |
Apple Mac OS X Server | =10.6.1 | |
Apple Mac OS X Server | =10.6.2 | |
macOS Yosemite | =10.6.1 | |
Apple Mac OS X Server | =10.6.0 | |
macOS Yosemite | =10.6.0 | |
macOS Yosemite | =10.6.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-0546 has a moderate severity level due to the potential for local users to delete arbitrary folders.
To fix CVE-2010-0546, it is recommended to update to Mac OS X 10.6.4 or later.
CVE-2010-0546 affects Apple Mac OS X versions 10.5.8 and 10.6 before 10.6.4.
CVE-2010-0546 involves a symlink attack that allows the deletion of arbitrary folders.
CVE-2010-0546 is not exploitable remotely; it requires local access to the system.