CVE-2008-2330Sensitive Information Exposure in Apple MAC OS X Server

Severity
4.9MEDIUMNVD
EPSS
0.1%
top 77.78%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 16
Latest updateMay 1

Description

slapconfig in Directory Services in Apple Mac OS X 10.5 through 10.5.4 allows local users to select a readable output file into which the server password will be written by an OpenLDAP system administrator, related to the mkfifo function, aka an "insecure file operation issue."

CVSS vector

AV:L/AC:L/C:C/I:N/A:NExploitability: 3.9 | Impact: 6.9

Affected Packages1 packages

NVDapple/mac_os_x_server6 versions+5

Patches

🔴Vulnerability Details

2
GHSA
GHSA-5rh2-3rgq-px65: slapconfig in Directory Services in Apple Mac OS X 102022-05-01
CVEList
CVE-2008-2330: slapconfig in Directory Services in Apple Mac OS X 102008-09-16

💥Exploits & PoCs

1
Exploit-DB
File Sharing Wizard 1.5.0 - Buffer Overflow (PoC)2010-06-15
CVE-2008-2330 — Sensitive Information Exposure in Apple | cvebase