Adobe Version Cue for Mac OS X Local Privilege Escalation Vulnerabilities
BID:14638
Info
Adobe Version Cue for Mac OS X Local Privilege Escalation Vulnerabilities
| Bugtraq ID: | 14638 |
| Class: | Design Error |
| CVE: |
CVE-2005-1842 CVE-2005-1843 |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 23 2005 12:00AM |
| Updated: | Jul 12 2009 05:06PM |
| Credit: | Discovery is credited to vade79. |
| Vulnerable: |
Adobe Version Cue 1.0.1 Adobe Version Cue 1.0 |
| Not Vulnerable: | |
Discussion
Adobe Version Cue for Mac OS X Local Privilege Escalation Vulnerabilities
Adobe Version Cue for Mac OS X is prone to two local privilege-escalation vulnerabilities that could allow a local attacker to load arbitrary libraries or overwrite files.
The first issue (CAN-2005-1842) allows a local user to overwrite arbitrary files in the context of the superuser through the VCNative application. This vulnerability permits privilege escalation, because files may be overwritten with custom data.
The second issue (CAN-2005-1843) allows a local user to load arbitrary libraries in the context of the superuser through the VCNative application. This will permit privilege escalation.
Adobe Version Cue 1.0 and 1.0.1 are vulnerable to this issue.
Adobe Version Cue for Mac OS X is prone to two local privilege-escalation vulnerabilities that could allow a local attacker to load arbitrary libraries or overwrite files.
The first issue (CAN-2005-1842) allows a local user to overwrite arbitrary files in the context of the superuser through the VCNative application. This vulnerability permits privilege escalation, because files may be overwritten with custom data.
The second issue (CAN-2005-1843) allows a local user to load arbitrary libraries in the context of the superuser through the VCNative application. This will permit privilege escalation.
Adobe Version Cue 1.0 and 1.0.1 are vulnerable to this issue.
Exploit / POC
Adobe Version Cue for Mac OS X Local Privilege Escalation Vulnerabilities
The following exploit code is available:
The following exploit code is available:
Solution / Fix
Adobe Version Cue for Mac OS X Local Privilege Escalation Vulnerabilities
Solution:
Adobe has released a fix:
Adobe Version Cue 1.0
Adobe Version Cue 1.0.1
Solution:
Adobe has released a fix:
Adobe Version Cue 1.0
-
Adobe Update 2 for Adobe Version Cue 1.x Workspace
http://www.adobe.com/support/downloads/detail.jsp?ftpID=2985
Adobe Version Cue 1.0.1
-
Adobe Update 2 for Adobe Version Cue 1.x Workspace
http://www.adobe.com/support/downloads/detail.jsp?ftpID=2985
References
Adobe Version Cue for Mac OS X Local Privilege Escalation Vulnerabilities
References:
References: