Apple Mac OS X Directory Services Passwd Privilege Escalation Vulnerabilities
BID:16910
Info
Apple Mac OS X Directory Services Passwd Privilege Escalation Vulnerabilities
| Bugtraq ID: | 16910 |
| Class: | Design Error |
| CVE: |
CVE-2005-2713 CVE-2005-2714 |
| Remote: | No |
| Local: | Yes |
| Published: | Mar 01 2006 12:00AM |
| Updated: | Mar 03 2006 06:51AM |
| Credit: | Reported by Ilja van Sprundel, vade79,, and iDefense. |
| Vulnerable: |
Apple Mac OS X Server 10.4.5 Apple Mac OS X Server 10.3.9 Apple Mac OS X 10.4.5 Apple Mac OS X 10.3.9 |
| Not Vulnerable: | |
Discussion
Apple Mac OS X Directory Services Passwd Privilege Escalation Vulnerabilities
Apple Mac OS X 'passwd' creates temporary files in an insecure manner. This could allow a local attacker to elevate their privileges.
These issues were originally described in BID 16907 Apple Mac OS X Security Update 2006-001 Multiple Vulnerabilities.
Apple Mac OS X 'passwd' creates temporary files in an insecure manner. This could allow a local attacker to elevate their privileges.
These issues were originally described in BID 16907 Apple Mac OS X Security Update 2006-001 Multiple Vulnerabilities.
Exploit / POC
Apple Mac OS X Directory Services Passwd Privilege Escalation Vulnerabilities
An exploit is not required.
To exploit the first issue, the attacker executes the following:
umask 0;/usr/bin/passwd -i file -l <filename>
where <filename> is the path and name of another file on the system.
The following code is available to exploit the second issue:
An exploit is not required.
To exploit the first issue, the attacker executes the following:
umask 0;/usr/bin/passwd -i file -l <filename>
where <filename> is the path and name of another file on the system.
The following code is available to exploit the second issue:
Solution / Fix
Apple Mac OS X Directory Services Passwd Privilege Escalation Vulnerabilities
Solution:
Apple has released advisory APPLE-SA-2006-03-01 to address these and other issues. Please see the referenced advisory for further details.
Apple Mac OS X 10.3.9
Apple Mac OS X Server 10.3.9
Apple Mac OS X Server 10.4.5
Apple Mac OS X 10.4.5
Solution:
Apple has released advisory APPLE-SA-2006-03-01 to address these and other issues. Please see the referenced advisory for further details.
Apple Mac OS X 10.3.9
-
Apple SecUpd2006-001Pan.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=09857&cat= 1&platform=osx&method=sa/SecUpd2006-001Pan.dmg
Apple Mac OS X Server 10.3.9
-
Apple SecUpdSrvr2006-001Pan.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=09858&cat= 1&platform=osx&method=sa/SecUpdSrvr2006-001Pan.dmg
Apple Mac OS X Server 10.4.5
-
Apple SecUpd2006-001Intel.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=09822&cat= 1&platform=osx&method=sa/SecUpd2006-001Intel.dmg -
Apple SecUpd2006-001Ti.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=09818&cat= 1&platform=osx&method=sa/SecUpd2006-001Ti.dmg
Apple Mac OS X 10.4.5
References
Apple Mac OS X Directory Services Passwd Privilege Escalation Vulnerabilities
References:
References: