Apple PPPDialer Insecure Log File Creation Symbolic Link Vulnerability
BID:11139
Info
Apple PPPDialer Insecure Log File Creation Symbolic Link Vulnerability
| Bugtraq ID: | 11139 |
| Class: | Access Validation Error |
| CVE: |
CVE-2004-0824 |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 07 2004 12:00AM |
| Updated: | Jul 12 2009 07:06AM |
| Credit: | This vulnerability was announced in a vendor advisory. |
| Vulnerable: |
Apple Mac OS X Server 10.3.5 Apple Mac OS X Server 10.3.4 Apple Mac OS X Server 10.2.8 Apple Mac OS X 10.3.5 Apple Mac OS X 10.3.4 Apple Mac OS X 10.2.8 |
| Not Vulnerable: | |
Discussion
Apple PPPDialer Insecure Log File Creation Symbolic Link Vulnerability
The Apple PPPDialer utility is reported to contain an insecure log file creation vulnerability. The result of this is that log files created by the application are created in a world writeable location.
A local attacker may possibly exploit this vulnerability to execute symbolic link file overwrite attacks.
Privilege escalation may be possible using this method of attack, if the attacker can control the data that is being written to the target file.
The Apple PPPDialer utility is reported to contain an insecure log file creation vulnerability. The result of this is that log files created by the application are created in a world writeable location.
A local attacker may possibly exploit this vulnerability to execute symbolic link file overwrite attacks.
Privilege escalation may be possible using this method of attack, if the attacker can control the data that is being written to the target file.
Exploit / POC
Apple PPPDialer Insecure Log File Creation Symbolic Link Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
Apple PPPDialer Insecure Log File Creation Symbolic Link Vulnerability
Solution:
Apple has released an advisory (APPLE-SA-0024-09-07) along with fixes to address this, and many other issues. Please see the referenced advisory for further information.
Apple Mac OS X 10.2.8
Apple Mac OS X Server 10.2.8
Apple Mac OS X 10.3.4
Apple Mac OS X Server 10.3.4
Apple Mac OS X 10.3.5
Apple Mac OS X Server 10.3.5
Solution:
Apple has released an advisory (APPLE-SA-0024-09-07) along with fixes to address this, and many other issues. Please see the referenced advisory for further information.
Apple Mac OS X 10.2.8
-
Apple SecUpd2004-09-07JagClient.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=04717&plat form=osx&method=sa/SecUpd2004-09-07JagClient.dmg
Apple Mac OS X Server 10.2.8
-
Apple SecUpdSrvr2004-09-07Jag.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=04716&plat form=osx&method=sa/SecUpdSrvr2004-09-07Jag.dmg
Apple Mac OS X 10.3.4
-
Apple SecUpd2004-09-07PanClient.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=04712&plat form=osx&method=sa/SecUpd2004-09-07PanClient.dmg
Apple Mac OS X Server 10.3.4
-
Apple SecUpdSrvr2004-09-07PanL.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=04713&plat form=osx&method=sa/SecUpdSrvr2004-09-07PanL.dmg
Apple Mac OS X 10.3.5
-
Apple SecUpd2004-09-07PanMClient.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=04715&plat form=osx&method=sa/SecUpd2004-09-07PanMClient.dmg
Apple Mac OS X Server 10.3.5
-
Apple SecUpdSrvr2004-09-07PanM.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=04714&plat form=osx&method=sa/SecUpdSrvr2004-09-07PanM.dmg
References
Apple PPPDialer Insecure Log File Creation Symbolic Link Vulnerability
References:
References: