First published: Thu Mar 24 2016(Updated: )
The Time Machine server in Server App in Apple OS X Server before 5.1 does not notify the user about ignored permissions during a backup, which makes it easier for remote attackers to obtain sensitive information in opportunistic circumstances by reading backup data that lacks intended restrictions.
Credit: product-security@apple.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple macOS Server | <=5.0.15 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-1774 is considered a medium severity vulnerability due to its potential to expose sensitive information.
To fix CVE-2016-1774, upgrade to Apple macOS Server version 5.1 or later.
CVE-2016-1774 affects Apple macOS Server versions prior to 5.1.
CVE-2016-1774 puts sensitive backup data at risk by not enforcing user permissions during the backup process.
Yes, CVE-2016-1774 can be exploited remotely under certain opportunistic circumstances.