Apple Mac OSX Internet Connect Insecure Temporary File Handling Symbolic Link Vulnerability
BID:10806
Info
Apple Mac OSX Internet Connect Insecure Temporary File Handling Symbolic Link Vulnerability
| Bugtraq ID: | 10806 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 25 2004 12:00AM |
| Updated: | Jul 25 2004 12:00AM |
| Credit: | Discovery is credited to B-r00t <[email protected]>. |
| Vulnerable: |
Apple Mac OS X 10.3.4 Apple Mac OS X 10.3.3 Apple Mac OS X 10.3.2 Apple Mac OS X 10.3.1 Apple Mac OS X 10.3 |
| Not Vulnerable: | |
Discussion
Apple Mac OSX Internet Connect Insecure Temporary File Handling Symbolic Link Vulnerability
It is reported that Internet Connect is prone to a local insecure temporary file handling symbolic link vulnerability. This issue is due to a design error that allows the application to insecurely create a file with a predictable name in the 'tmp' directory.
A successful attack can eventually allow a local attacker to gain super user privileges.
This issue is reported to affect Mac OS X 10.3.4. It is likely that other versions are affected as well.
It is reported that Internet Connect is prone to a local insecure temporary file handling symbolic link vulnerability. This issue is due to a design error that allows the application to insecurely create a file with a predictable name in the 'tmp' directory.
A successful attack can eventually allow a local attacker to gain super user privileges.
This issue is reported to affect Mac OS X 10.3.4. It is likely that other versions are affected as well.
Exploit / POC
Apple Mac OSX Internet Connect Insecure Temporary File Handling Symbolic Link Vulnerability
Proof of concept has been developed by the researcher who discovered this issue. The proof of concept demonstrates the possibility of gaining super user privileges.
Proof of concept has been developed by the researcher who discovered this issue. The proof of concept demonstrates the possibility of gaining super user privileges.
Solution / Fix
Apple Mac OSX Internet Connect Insecure Temporary File Handling Symbolic Link Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Apple Mac OSX Internet Connect Insecure Temporary File Handling Symbolic Link Vulnerability
References:
References: