The indexing functionality in Spotlight in Apple OS X before 10.10.2 writes memory contents to an external hard drive, which allows local users to obtain sensitive information by reading from this drive.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/100528 | vdb entry |
http://www.securitytracker.com/id/1031650 | vdb entry |
http://support.apple.com/HT204244 | vendor advisory |
http://lists.apple.com/archives/security-announce/2015/Jan/msg00003.html | vendor advisory |