CVE Vulnerabilities

CVE-2010-0545

Published: Jun 17, 2010 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.4 MEDIUM
AV:L/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The Finder in DesktopServices in Apple Mac OS X 10.5.8, and 10.6 before 10.6.4, does not set the expected file ownerships during an Apply to enclosed items action, which allows local users to bypass intended access restrictions via normal filesystem operations.

Affected Software

NameVendorStart VersionEnd Version
Mac_os_xApple10.5.8 (including)10.5.8 (including)
Mac_os_xApple10.6.0 (including)10.6.0 (including)
Mac_os_xApple10.6.1 (including)10.6.1 (including)
Mac_os_xApple10.6.2 (including)10.6.2 (including)
Mac_os_xApple10.6.3 (including)10.6.3 (including)
Mac_os_x_serverApple10.5.8 (including)10.5.8 (including)
Mac_os_x_serverApple10.6.0 (including)10.6.0 (including)
Mac_os_x_serverApple10.6.1 (including)10.6.1 (including)
Mac_os_x_serverApple10.6.2 (including)10.6.2 (including)
Mac_os_x_serverApple10.6.3 (including)10.6.3 (including)

References