CVE-2004-1084
published 2004-12-02CVE-2004-1084: Apache for Apple Mac OS X 10.2.8 and 10.3.6 allows remote attackers to read files and resource fork content via HTTP requests to certain special file names…
PriorityP419medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
1.64%
73.8th percentile
Apache for Apple Mac OS X 10.2.8 and 10.3.6 allows remote attackers to read files and resource fork content via HTTP requests to certain special file names related to multiple data streams in HFS+, which bypass Apache file handles.
Affected
35 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | darwin_streaming_server | — | — |
| apple | darwin_streaming_server | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
CWE
Improper Handling of File Names that Identify Virtual Resources
mitre_cwe
CWE-66 Improper Handling of File Names that Identify Virtual Resources
CWE-66: Improper Handling of File Names that Identify Virtual Resources
The product does not handle or incorrectly handles a file name that identifies a "virtual" resource that is not directly specified within the directory that is associated with the file name, causing the product to perform file-based operations on a resource that is not a file.
Virtual file names are represented like normal file names, but they are effectively aliases for other resources that do not behave like normal files. Depending on their functionality, they could be alternate entities. They are not necessarily listed in directories.
Modes of Introduction:
Phase: Implementation
Phase: Operation
Common Consequences:
Scope: Other. Impact: Other.
Detection Methods:
Automated Static Analysis - Binary or Bytecode:
CWE
Improper Handling of Apple HFS+ Alternate Data Stream Path
mitre_cwe
CWE-72 Improper Handling of Apple HFS+ Alternate Data Stream Path
CWE-72: Improper Handling of Apple HFS+ Alternate Data Stream Path
The product does not properly handle special paths that may identify the data or resource fork of a file on the HFS+ file system.
If the product chooses actions to take based on the file name, then if an attacker provides the data or resource fork, the product may take unexpected actions. Further, if the product intends to restrict access to a file, then an attacker might still be able to bypass intended access restrictions by requesting the data or resource fork for that file.
Background: The Apple HFS+ file system permits files to have multiple data input streams, accessible through special paths. The Mac OS X operating system provides a way to access the different data input streams through special paths and as an ext
http://lists.apple.com/archives/security-announce/2004/Dec/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2005//Aug/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2005/Aug/msg00000.htmlhttp://secunia.com/advisories/13362/http://www.ciac.org/ciac/bulletins/p-049.shtmlhttp://www.securityfocus.com/bid/11802https://exchange.xforce.ibmcloud.com/vulnerabilities/18349http://lists.apple.com/archives/security-announce/2004/Dec/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2005//Aug/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2005/Aug/msg00000.htmlhttp://secunia.com/advisories/13362/http://www.ciac.org/ciac/bulletins/p-049.shtmlhttp://www.securityfocus.com/bid/11802https://exchange.xforce.ibmcloud.com/vulnerabilities/18349
2004-12-02
Published