The code-signing subsystem in Apple OS X before 10.11.4 does not properly verify file ownership, which allows local users to determine the existence of arbitrary files via unspecified vectors.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Mac_os_x |
Apple |
* |
10.11.3 (including) |
References