First published: Thu Feb 27 2014(Updated: )
Finder in Apple OS X before 10.9.2 does not ensure ACL integrity after the viewing of file ACL information, which allows local users to bypass intended access restrictions in opportunistic circumstances via standard filesystem operations on a file with a damaged ACL.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
macOS Yosemite | <=10.9.1 | |
macOS Yosemite | =10.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-1264 has a severity rating that indicates it allows local users to bypass intended access restrictions.
To fix CVE-2014-1264, it is recommended to upgrade to OS X version 10.9.2 or later.
CVE-2014-1264 affects users of Apple OS X versions prior to 10.9.2.
CVE-2014-1264 is a file permission vulnerability that affects ACL integrity.
CVE-2014-1264 is a local vulnerability and cannot be exploited remotely.