Skip to main content

Apple Macintosh OS X .DS_Store Directory Listing DisclosureVulnerability

posted onSeptember 13, 2001
by hitbsecnews

A vulnerability has been found in certain configurations of Macintosh OS X.

A remote attacker may read obtain web directory content information by submitting a URL
to the vulnerable host's web service of the following form:

http://www.example.com/target_directory/.DS_store.

This information could provide an attacker with sensitive information including system
configuration, installed applications, etc. Properly exploited, this information could allow an
attacker to further compromise the security of the host.

L33tdawg: There's information on a temporary workaround as well as list of which versions are vulnerable in the read more.

Temporary workaround: disallow remote access to .DS_store files.

bugtraq id
3324
class
Access Validation Error
cve
CVE-MAP-NOMATCH
remote
Yes
local
No
published
September 11, 2001
updated
September 11, 2001
vulnerable
Apple MacOS X 10.0.4
Apple MacOS X 10.0.3
Apple MacOS X 10.0.2
Apple MacOS X 10.0.1
Apple MacOS X 10.0

Source

Tags

Networking

You May Also Like

Recent News

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th

Friday, June 7th

Thursday, June 6th

Wednesday, June 5th