A vulnerability exists when Apache webserver is used with Mac OS X Client. Due to a flaw in Mac OS file permissions, an issue exists which could disclose the contents of a particular web directory to an unauthorized user. Requesting a URL with the relative path of a '.DS_Store' file, will reveal the contents of the requested directory. This vulnerability could be used in conjunction with a previously discovered issue (BID 2852), which causes files to be arbitrarily disclosed through mixed case file requests.
A vulnerability exists when Apache webserver is used with Mac OS X Client. Due to a flaw in Mac OS file permissions, an issue exists which could disclose the contents of a particular web directory to an unauthorized user. Requesting a URL with the relative path of a '.DS_Store' file, will reveal the contents of the requested directory. This vulnerability could be used in conjunction with a previously discovered issue (BID 2852), which causes files to be arbitrarily disclosed through mixed case file requests.