PT-2005-1229 · Apple · Macos X
Kevin Finisterre
·
Published
2005-01-29
·
Updated
2018-08-13
·
CVE-2005-0125
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Mac OS X versions 10.3.7 and earlier
Description
The issue concerns the "at" commands, which do not properly drop privileges. This allows local users to delete arbitrary files, execute arbitrary programs, or read arbitrary files. Specifically, the atrm command can be used to delete files, while the batch command with the -f argument can be used to execute programs or read files by generating a readable job file.
Recommendations
For Mac OS X versions 10.3.7 and earlier, consider disabling the "at" commands until a patch is available. As a temporary workaround, restrict access to the atrm and batch commands to minimize the risk of exploitation. Avoid using the -f argument with the batch command until the issue is resolved.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Macos X