The FSFindFolder API in CarbonCore in Apple Mac OS X before 10.6.7 provides a world-readable directory in response to a call with the kTemporaryFolderType flag, which allows local users to obtain potentially sensitive information by accessing this directory.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published: 2011-03-23T01:00:00Z

Updated: 2024-09-17T00:46:27.868Z

Reserved: 2010-12-23T00:00:00Z

Link: CVE-2011-0178

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2011-03-23T02:00:04.173

Modified: 2024-11-21T01:23:29.067

Link: CVE-2011-0178

cve-icon Redhat

No data.