CVE Vulnerabilities

CVE-2014-1347

Published: May 18, 2014 | Modified: May 19, 2014
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.4 MEDIUM
AV:L/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Apple iTunes before 11.2.1 on OS X sets world-writable permissions for /Users and /Users/Shared during reboots, which allows local users to modify files, and consequently obtain access to arbitrary user accounts, via standard filesystem operations.

Affected Software

Name Vendor Start Version End Version
Itunes Apple * 11.2 (including)
Itunes Apple 11.0 (including) 11.0 (including)
Itunes Apple 11.0.1 (including) 11.0.1 (including)
Itunes Apple 11.0.2 (including) 11.0.2 (including)
Itunes Apple 11.0.3 (including) 11.0.3 (including)
Itunes Apple 11.0.4 (including) 11.0.4 (including)
Itunes Apple 11.0.5 (including) 11.0.5 (including)
Itunes Apple 11.1 (including) 11.1 (including)
Itunes Apple 11.1.1 (including) 11.1.1 (including)
Itunes Apple 11.1.2 (including) 11.1.2 (including)
Itunes Apple 11.1.3 (including) 11.1.3 (including)
Itunes Apple 11.1.4 (including) 11.1.4 (including)
Itunes Apple 11.1.5 (including) 11.1.5 (including)

References