CVE Reference: CVE-2004-1083

NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2004-1083

Description:
Apache for Apple Mac OS X 10.2.8 and 10.3.6 restricts access to files in a case sensitive manner, but the Apple HFS+ filesystem accesses files in a case insensitive manner, which allows remote attackers to read .DS_Store files and files beginning with ".ht" using alternate capitalization.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/18348

SAID
  Secunia Advisory: SA13362

CIAC
  http://www.ciac.org/ciac/bulletins/p-049.shtml

BID
  11802

APPLE
  http://lists.apple.com/archives/security-announce/2005//Aug/msg00001.html
  http://lists.apple.com/archives/security-announce/2005//Aug/msg00000.html
  http://lists.apple.com/archives/security-announce/2004/Dec/msg00000.html


Return to the previous page.