Apple Macintosh OS X .DS_Store Directory Listing DisclosureVulnerability
A vulnerability has been found in certain configurations of Macintosh OS X.
A remote attacker may read obtain web directory content information by submitting a URL
to the vulnerable host's web service of the following form:
http://www.example.com/target_directory/.DS_store.
This information could provide an attacker with sensitive information including system
configuration, installed applications, etc. Properly exploited, this information could allow an
attacker to further compromise the security of the host.
L33tdawg: There's information on a temporary workaround as well as list of which versions are vulnerable in the read more.
Temporary workaround: disallow remote access to .DS_store files.
bugtraq id
3324
class
Access Validation Error
cve
CVE-MAP-NOMATCH
remote
Yes
local
No
published
September 11, 2001
updated
September 11, 2001
vulnerable
Apple MacOS X 10.0.4
Apple MacOS X 10.0.3
Apple MacOS X 10.0.2
Apple MacOS X 10.0.1
Apple MacOS X 10.0