MacOS X Client Apache Directory Contents Disclosure Vulnerability

A vulnerability exists when Apache webserver is used with Mac OS X Client.

Due to a flaw in Mac OS file permissions, an issue exists which could disclose the contents of a particular web directory to an unauthorized user. Requesting a URL with the relative path of a '.DS_Store' file, will reveal the contents of the requested directory.

This vulnerability could be used in conjunction with a previously discovered issue (BID 2852), which causes files to be arbitrarily disclosed through mixed case file requests.


 

Privacy Statement
Copyright 2010, SecurityFocus