Vulnerability Description
Certain system calls in Apple Mac OS X 10.4.1 do not properly enforce the permissions of certain directories without the POSIX read bit set, but with the execute bits set for group or other, which allows local users to list files in otherwise restricted directories.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apple | Mac Os X | 10.4.1 |
References
- http://lists.apple.com/archives/security-announce/2005/May/msg00004.htmlPatchVendor Advisory
- http://lists.apple.com/archives/security-announce/2005/May/msg00004.htmlPatchVendor Advisory
FAQ
What is CVE-2005-1472?
CVE-2005-1472 is a vulnerability with a CVSS score of 2.1 (LOW). Certain system calls in Apple Mac OS X 10.4.1 do not properly enforce the permissions of certain directories without the POSIX read bit set, but with the execute bits set for group or other, which all...
How severe is CVE-2005-1472?
CVE-2005-1472 has been rated LOW with a CVSS base score of 2.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2005-1472?
Check the references section above for vendor advisories and patch information. Affected products include: Apple Mac Os X.