← Back

CVE-2004-0922

nvd nist
Published: Jan 27, 2005Modified: Apr 16, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:P/I:N/A:N
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

AFP Server on Mac OS X 10.3.x to 10.3.5, under certain conditions, does not properly set the guest group ID, which causes AFP to change a write-only AFP Drop Box to be read-write when the Drop Box is on a share that is mounted by a guest, which allows attackers to read the Drop Box.

Affected (35)

3 products
Quicktime
Mac Os X
Mac Os X Server
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
Apple
Version 5.0.2
Version 6.0
Version 6.1
Version 6.5.1
Version 6.5
Configuration B
30 vulnerable
Vulnerable SoftwareAffected Versions
Apple
Version 10.2.1
Version 10.2.2
Version 10.2.3
Version 10.2.4
Version 10.2.5
Version 10.2.6
Version 10.2.7
Version 10.2.8
Version 10.2
Version 10.3.1
Version 10.3.2
Version 10.3.3
Version 10.3.4
Version 10.3.5
Version 10.3
Apple
Version 10.2.1
Version 10.2.2
Version 10.2.3
Version 10.2.4
Version 10.2.5
Version 10.2.6
Version 10.2.7
Version 10.2.8
Version 10.2
Version 10.3.1
Version 10.3.2
Version 10.3.3
Version 10.3.4
Version 10.3.5
Version 10.3

References (4)

Source: cve@mitre.org
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory

Timeline

No history available yet.