CVE-2008-2331Apple MAC OS X vulnerability

CWE-2644 documents4 sources
Severity
5.0MEDIUMNVD
EPSS
0.2%
top 56.81%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 16
Latest updateMay 1

Description

Finder in Apple Mac OS X 10.5 through 10.5.4 does not properly update permission data in the Get Info window after a lock operation that modifies Sharing & Permissions in a filesystem, which might allow local users to leverage weak permissions that were not intended by an administrator.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

NVDapple/mac_os_x5 versions+4
NVDapple/mac_os_x_server5 versions+4

Patches

🔴Vulnerability Details

2
GHSA
GHSA-qmwg-ww4r-p7pw: Finder in Apple Mac OS X 102022-05-01
CVEList
CVE-2008-2331: Finder in Apple Mac OS X 102008-09-16

💥Exploits & PoCs

1
Exploit-DB
File Sharing Wizard 1.5.0 - Remote Overflow (SEH)2010-06-17
CVE-2008-2331 — Apple MAC OS X vulnerability | cvebase