PT-2003-1358 · Trublue · Trublueenvironment
Published
2003-03-03
·
Updated
2008-09-11
·
CVE-2003-0088
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
TruBlueEnvironment for MacOS versions 10.2.3 and earlier
Description
The issue allows local users to overwrite or create arbitrary files and gain root privileges by setting a certain environment variable used to write debugging information.
Recommendations
For TruBlueEnvironment for MacOS versions 10.2.3 and earlier, consider restricting the ability to set environment variables used for debugging information until a patch is available. As a temporary workaround, limit the privileges of users who can set these variables to prevent potential exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Trublueenvironment