PT-2007-1816 · Apple · Activity Monitor.App+4
Publicado
2007-01-18
·
Atualizado
2017-10-19
·
CVE-2007-0345
CVSS v2.0
6.8
Média
| Vetor | AV:L/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Mac OS X version 10.4.8
Description:
The issue concerns weak permissions in certain programs within Mac OS X, specifically the Activity Monitor.app, Keychain Access.app, and ODBC Administrator.app. These weak permissions allow local admin users to modify the programs and subsequently gain root privileges by performing permissions repair via diskutil.
Recommendations:
For Mac OS X version 10.4.8, consider restricting write access to the affected programs to prevent local admin users from modifying them. As a temporary workaround, avoid using the diskutil permissions repair feature until a fix is available.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Activity Monitor.App
Keychain Access.App
Macos X
Odbc Administrator.App
Diskutil