PT-2007-1816 · Apple · Activity Monitor.App+4

Publicado

2007-01-18

·

Atualizado

2017-10-19

·

CVE-2007-0345

CVSS v2.0

6.8

Média

VetorAV:L/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Mac OS X version 10.4.8
Description: The issue concerns weak permissions in certain programs within Mac OS X, specifically the Activity Monitor.app, Keychain Access.app, and ODBC Administrator.app. These weak permissions allow local admin users to modify the programs and subsequently gain root privileges by performing permissions repair via diskutil.
Recommendations: For Mac OS X version 10.4.8, consider restricting write access to the affected programs to prevent local admin users from modifying them. As a temporary workaround, avoid using the diskutil permissions repair feature until a fix is available.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-0345

Produtos afetados

Activity Monitor.App
Keychain Access.App
Macos X
Odbc Administrator.App
Diskutil