Weblog in Mac OS X Server 10.4.11 does not properly check an error condition when a weblog posting access control list is specified for a user that has multiple short names, which might allow attackers to bypass intended access restrictions.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/31681 | vdb entry patch |
http://www.securityfocus.com/bid/31718 | vdb entry |
http://secunia.com/advisories/32222 | third party advisory vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/45787 | vdb entry |
http://www.vupen.com/english/advisories/2008/2780 | vdb entry |
http://www.securitytracker.com/id?1021030 | vdb entry |
http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.html | vendor advisory |
http://support.apple.com/kb/HT3216 | vendor advisory |