ID

VAR-200305-0065


CVE

CVE-2003-0198


TITLE

Apple MacOS X DropBox Folder Remote Information Disclosure Vulnerability

Trust: 0.6

sources: CNNVD: CNNVD-200305-011

DESCRIPTION

Mac OS X before 10.2.5 allows guest users to modify the permissions of the DropBox folder and read unauthorized files. A vulnerability has been discovered in Apple MacOS X 10.2.4 and earlier. The problem occurs when various file sharing services are enabled. The issue occurs in the privileges granted to 'guest' users, when accessing shared folders. Due to a design error, it may be possible for an unprivileged user to change the permissions of a write-only directory, effectively revealing its contents. Information obtained through exploiting this vulnerability could aid an attacker in launching further attacks against a target system. Mac OS X is an operating system used on Mac machines, based on the BSD system. An issue in the way Mac OS X handles file-sharing services could allow remote attackers to gain access to sensitive file information. Using this information can help attackers further attack the system

Trust: 1.26

sources: NVD: CVE-2003-0198 // BID: 7324 // VULHUB: VHN-7027

AFFECTED PRODUCTS

vendor:applemodel:mac os xscope:eqversion:10.0.4

Trust: 1.6

vendor:applemodel:mac os xscope:eqversion:10.1

Trust: 1.6

vendor:applemodel:mac os xscope:eqversion:10.0.1

Trust: 1.6

vendor:applemodel:mac os xscope:eqversion:10.1.1

Trust: 1.6

vendor:applemodel:mac os xscope:eqversion:10.1.3

Trust: 1.6

vendor:applemodel:mac os x serverscope:eqversion:10.2.4

Trust: 1.6

vendor:applemodel:mac os xscope:eqversion:10.1.2

Trust: 1.6

vendor:applemodel:mac os xscope:eqversion:10.0

Trust: 1.6

vendor:applemodel:mac os xscope:eqversion:10.0.3

Trust: 1.6

vendor:applemodel:mac os xscope:eqversion:10.0.2

Trust: 1.6

vendor:applemodel:mac os xscope:eqversion:10.1.4

Trust: 1.0

vendor:applemodel:mac os xscope:eqversion:10.2.2

Trust: 1.0

vendor:applemodel:mac os xscope:eqversion:10.1.5

Trust: 1.0

vendor:applemodel:mac os x serverscope:eqversion:10.2.2

Trust: 1.0

vendor:applemodel:mac os xscope:eqversion:10.2.1

Trust: 1.0

vendor:applemodel:mac os x serverscope:eqversion:10.2

Trust: 1.0

vendor:applemodel:mac os x serverscope:eqversion:10.2.1

Trust: 1.0

vendor:applemodel:mac os xscope:eqversion:10.2.4

Trust: 1.0

vendor:applemodel:mac os x serverscope:eqversion:10.0

Trust: 1.0

vendor:applemodel:mac os xscope:eqversion:10.2.3

Trust: 1.0

vendor:applemodel:mac os x serverscope:eqversion:10.2.3

Trust: 1.0

vendor:applemodel:mac os serverscope:eqversion:x10.2.4

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x10.2.3

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x10.2.2

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x10.2.1

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x10.2

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x10.0

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.2.4

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.2.3

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.2.2

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.2.1

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.1.5

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.1.4

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.1.3

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.1.2

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.1.1

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.1

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.0.4

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.0.3

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.0.2

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.0.1

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.0

Trust: 0.3

vendor:applemodel:mac os serverscope:neversion:x10.2.5

Trust: 0.3

vendor:applemodel:mac osscope:neversion:x10.2.5

Trust: 0.3

sources: BID: 7324 // CNNVD: CNNVD-200305-011 // NVD: CVE-2003-0198

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2003-0198
value: MEDIUM

Trust: 1.0

CNNVD: CNNVD-200305-011
value: MEDIUM

Trust: 0.6

VULHUB: VHN-7027
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2003-0198
severity: MEDIUM
baseScore: 6.4
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 4.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

VULHUB: VHN-7027
severity: MEDIUM
baseScore: 6.4
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 4.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-7027 // CNNVD: CNNVD-200305-011 // NVD: CVE-2003-0198

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

sources: NVD: CVE-2003-0198

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200305-011

TYPE

Design Error

Trust: 0.9

sources: BID: 7324 // CNNVD: CNNVD-200305-011

EXTERNAL IDS

db:NVDid:CVE-2003-0198

Trust: 2.0

db:CNNVDid:CNNVD-200305-011

Trust: 0.7

db:BIDid:7324

Trust: 0.4

db:VULHUBid:VHN-7027

Trust: 0.1

sources: VULHUB: VHN-7027 // BID: 7324 // CNNVD: CNNVD-200305-011 // NVD: CVE-2003-0198

REFERENCES

url:http://lists.apple.com/mhonarc/security-announce/msg00028.html

Trust: 1.7

url:http://www.info.apple.com/usen/security/security_updates.html

Trust: 0.3

sources: VULHUB: VHN-7027 // BID: 7324 // CNNVD: CNNVD-200305-011 // NVD: CVE-2003-0198

CREDITS

Dave G.※ daveg@atstake.com

Trust: 0.6

sources: CNNVD: CNNVD-200305-011

SOURCES

db:VULHUBid:VHN-7027
db:BIDid:7324
db:CNNVDid:CNNVD-200305-011
db:NVDid:CVE-2003-0198

LAST UPDATE DATE

2024-08-14T14:00:52.290000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-7027date:2008-09-10T00:00:00
db:BIDid:7324date:2009-07-11T21:06:00
db:CNNVDid:CNNVD-200305-011date:2005-10-20T00:00:00
db:NVDid:CVE-2003-0198date:2008-09-10T19:18:13.383

SOURCES RELEASE DATE

db:VULHUBid:VHN-7027date:2003-05-05T00:00:00
db:BIDid:7324date:2003-04-10T00:00:00
db:CNNVDid:CNNVD-200305-011date:2003-04-10T00:00:00
db:NVDid:CVE-2003-0198date:2003-05-05T04:00:00