PT-2003-1358 · Trublue · Trublueenvironment
Publicado
2003-03-03
·
Atualizado
2008-09-11
·
CVE-2003-0088
CVSS v2.0
7.2
Alta
| Vetor | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
TruBlueEnvironment for MacOS versions 10.2.3 and earlier
Description
The issue allows local users to overwrite or create arbitrary files and gain root privileges by setting a certain environment variable used to write debugging information.
Recommendations
For TruBlueEnvironment for MacOS versions 10.2.3 and earlier, consider restricting the ability to set environment variables used for debugging information until a patch is available. As a temporary workaround, limit the privileges of users who can set these variables to prevent potential exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Trublueenvironment