The FSFindFolder API in CarbonCore in Apple Mac OS X before 10.6.7 provides a world-readable directory in response to a call with the kTemporaryFolderType flag, which allows local users to obtain potentially sensitive information by accessing this directory.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://lists.apple.com/archives/security-announce/2011/Mar/msg00006.html | patch vendor advisory |
http://support.apple.com/kb/HT4581 | patch vendor advisory |