Vulnerability Name: | CVE-2014-1264 (CCN-91410) | ||||||||
Assigned: | 2014-02-25 | ||||||||
Published: | 2014-02-25 | ||||||||
Updated: | 2014-03-10 | ||||||||
Summary: | Finder in Apple OS X before 10.9.2 does not ensure ACL integrity after the viewing of file ACL information, which allows local users to bypass intended access restrictions in opportunistic circumstances via standard filesystem operations on a file with a damaged ACL. | ||||||||
CVSS v3 Severity: | 5.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 3.3 Low (CVSS v2 Vector: AV:L/AC:M/Au:N/C:P/I:P/A:N) 2.5 Low (Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:P/I:P/A:N/E:U/RL:OF/RC:C)
3.4 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-264 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2014-1264 Source: CCN Type: Apple Web site About the security content of OS X Mavericks v10.9.2 and Security Update 2014-001 Source: CONFIRM Type: Vendor Advisory http://support.apple.com/kb/HT6150 Source: XF Type: UNKNOWN apple-macosx-cve20141264-unauth-access(91410) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |