lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <20060316074957.08B2B150A@lists.grok.org.uk> Date: Thu Mar 16 08:08:31 2006 From: adf at code511.com (adf@...e511.com) Subject: !ADVISORY! + x Thu Mar 16 02:49:51 EST 2006 x + Directory Transversal in Apple MacOSX !ADVISORY! + x Thu Mar 16 02:49:51 EST 2006 x + Directory Transversal in Apple MacOSX ++++++++++++++++++++++++++++++++++++++++++++++++++++ 1. BACKGROUND ++++++++++++++++++++++++++++++++++++++++++++++++++++ There has been no background. ++++++++++++++++++++++++++++++++++++++++++++++++++++ 2. DESCRIPTION ++++++++++++++++++++++++++++++++++++++++++++++++++++ Remote exploitation of a directory traversal vulnerability in Apple MacOSX could allow attackers to overwrite or view arbitrary files with user-supplied contents. ++++++++++++++++++++++++++++++++++++++++++++++++++++ 3. VENDOR RESPONSE ++++++++++++++++++++++++++++++++++++++++++++++++++++ Apple MacOSX was offered no explanation. ++++++++++++++++++++++++++++++++++++++++++++++++++++ APPENDIX A VENDOR INFORMATION ++++++++++++++++++++++++++++++++++++++++++++++++++++ http://www.apple.com/macosx/ ++++++++++++++++++++++++++++++++++++++++++++++++++++ APPENDIX B REFERENCES ++++++++++++++++++++++++++++++++++++++++++++++++++++ RFC 4112