MEDIUM · 5.0

CVE-2011-0203

Absolute path traversal vulnerability in xftpd in the FTP Server component in Apple Mac OS X before 10.6.8 allows remote attackers to list arbitrary directories by using the root directory as the star...

Vulnerability Description

Absolute path traversal vulnerability in xftpd in the FTP Server component in Apple Mac OS X before 10.6.8 allows remote attackers to list arbitrary directories by using the root directory as the starting point of a recursive listing.

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
AppleMac Os X Server10.6.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2011-0203?

CVE-2011-0203 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Absolute path traversal vulnerability in xftpd in the FTP Server component in Apple Mac OS X before 10.6.8 allows remote attackers to list arbitrary directories by using the root directory as the star...

How severe is CVE-2011-0203?

CVE-2011-0203 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2011-0203?

Check the references section above for vendor advisories and patch information. Affected products include: Apple Mac Os X Server.