Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Apple iTunes before 11.2.1 on OS X sets world-writable permissions for /Users and /Users/Shared during reboots, which allows local users to modify files, and consequently obtain access to arbitrary user accounts, via standard filesystem operations.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Apple iTunes 权限许可和访问控制漏洞
Vulnerability Description
Apple Apple iTunes是美国苹果(Apple)公司的一套媒体播放器应用程序,它主要用于对数字音乐和视频文件进行播放以及管理。 基于OS X平台的Apple iTunes 11.2及之前的版本中存在安全漏洞,该漏洞源于在重新启动期间,程序对/Users和/Users/Shared目录设置全局可写权限。本地攻击者可利用该漏洞修改文件,获取任意用户账户的访问权限。
CVSS Information
N/A
Vulnerability Type
N/A