CVE-2010-1381: Low severity apple ios and macos vulnerability
Published Jun 17, 2010
·Updated
The default configuration of SMB File Server in Apple Mac OS X 10.5.8, and 10.6 before 10.6.4, enables support for wide links, which allows remote authenticated users to access arbitrary files via vectors involving symbolic links. NOTE: this might overlap CVE-2010-0926.
Affected Software
10 affected components
Apple iOS and macOS=10.5.8
Apple Mac OS X Server=10.5.8
Apple Mac OS X Server=10.6.3
Apple iOS and macOS=10.6.3
Apple Mac OS X Server=10.6.1
Apple Mac OS X Server=10.6.2
Apple iOS and macOS=10.6.1
Apple Mac OS X Server=10.6.0
Apple iOS and macOS=10.6.0
Apple iOS and macOS=10.6.2
Remediation
Patch Available
Patch Available
Event History
Jun 17, 2010
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2010-1381?
CVE-2010-1381 is classified as a moderate severity vulnerability.
2
How do I fix CVE-2010-1381?
To fix CVE-2010-1381, upgrade your Apple Mac OS X to version 10.6.4 or later.
3
What versions of macOS are affected by CVE-2010-1381?
CVE-2010-1381 affects Apple Mac OS X versions 10.5.8 and 10.6.x prior to 10.6.4.
4
What type of attack does CVE-2010-1381 facilitate?
CVE-2010-1381 allows remote authenticated users to access arbitrary files through symbolic links.
5
Is there a workaround for CVE-2010-1381?
Disabling wide links in the SMB File Server configuration can serve as a temporary workaround for CVE-2010-1381.