PT-2007-1602 · Apple · Diskutil+2

Publicado

2007-01-09

·

Atualizado

2011-03-08

·

CVE-2007-0117

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions DiskManagementTool in DiskManagement.framework version 92.29
Description The issue arises from the improper validation of Bill of Materials (BOM) files by the DiskManagementTool. This allows attackers to gain privileges through a BOM file located under /Library/Receipts/, which can trigger arbitrary file permission changes when a diskutil permission repair operation is executed.
Recommendations For DiskManagementTool in DiskManagement.framework version 92.29, consider restricting access to the /Library/Receipts/ directory to minimize the risk of exploitation until a proper fix is applied.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-0117

Produtos afetados

Diskmanagement.Framework
Diskmanagementtool
Diskutil