zerofox logo
Advisories

ZeroFox Intelligence Exploit Profile – CVE-2018-6470

|by Alpha Team

banner image

ZeroFox Intelligence Exploit Profile – CVE-2018-6470

Product Serial: P-2023-05-25a

TLP:CLEAR

In this exploit profile, ZeroFox Intelligence provides an overview of CVE-2018-6470, which is an information disclosure vulnerability within Nibbleblog 4.0.5 installed on macOS that creates a .DS_Store file in each Directory.

Standing Intelligence Requirements

Deep Dark Web and Criminal Underground DDW

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:

https://cloud.zerofox.com/intelligence/advisories/14956

Link to Download View the full report here.

Scope Note

ZeroFox Intelligence is derived from a variety of sources, including—but not limited to—curated open-source accesses, vetted social media, proprietary data sources, and direct access to threat actors and groups through covert communication channels. Information relied upon to complete any report cannot always be independently verified. As such, ZeroFox applies rigorous analytic standards and tradecraft in accordance with best practices and includes caveat language and source citations to clearly identify the veracity of our Intelligence reporting and substantiate our assessments and recommendations. All sources used in this particular Intelligence product were identified prior to 12:00 PM (EDT) on May 19, 2023; per cyber hygiene best practices, caution is advised when clicking on any third-party links.

Current Description

Nibbleblog 4.0.5 on macOS defaults to having .DS_Store in each directory, causing DS_Store information to leak.

Tags: tlp:clear,  vulnerability/exploit,  all industries,  global