CVE-2011-0178: Infoleak
Published Mar 23, 2011
·Updated
The FSFindFolder API in CarbonCore in Apple Mac OS X before 10.6.7 provides a world-readable directory in response to a call with the kTemporaryFolderType flag, which allows local users to obtain potentially sensitive information by accessing this directory.
Affected Software
16 affected components
Apple iOS and macOS=10.6.3
Apple iOS and macOS<=10.6.6
Apple CarbonCore
Apple iOS and macOS=10.6.1
Apple iOS and macOS=10.6.0
Apple iOS and macOS=10.6.2
Apple iOS and macOS=10.6.4
Apple iOS and macOS=10.6.5
Apple Mac OS X Server=10.6.3
Apple Mac OS X Server<=10.6.6
Apple Mac OS X Server=10.6.4
Apple Mac OS X Server=10.6.5
Apple Mac OS X Server=10.6.1
Apple Mac OS X Server=10.6.2
Apple Mac OS X Server=10.6.0
Apple CarbonCore
Remediation
Patch Available
Event History
Mar 23, 2011
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-0178?
CVE-2011-0178 is considered a medium severity vulnerability.
2
How do I fix CVE-2011-0178?
To fix CVE-2011-0178, update your Mac OS X to version 10.6.7 or later.
3
Which versions of Mac OS X are affected by CVE-2011-0178?
CVE-2011-0178 affects Mac OS X versions 10.6.0 to 10.6.6.
4
What kind of information can be exposed by CVE-2011-0178?
CVE-2011-0178 may allow local users to access potentially sensitive information stored in a world-readable directory.
5
Is there a specific API related to CVE-2011-0178?
Yes, the vulnerability is associated with the FSFindFolder API in the CarbonCore.