Symantec LiveUpdate for Macintosh Local Privilege Escalation Vulnerability
BID:17571
Info
Symantec LiveUpdate for Macintosh Local Privilege Escalation Vulnerability
| Bugtraq ID: | 17571 |
| Class: | Design Error |
| CVE: |
CVE-2006-1836 |
| Remote: | No |
| Local: | Yes |
| Published: | Apr 17 2006 12:00AM |
| Updated: | Jun 27 2007 07:08PM |
| Credit: | DigitalMunition.com is credited with the discovery of this issue. |
| Vulnerable: |
Symantec Norton Utilities for Macintosh 8.0 Symantec Norton System Works for Macintosh 3.0 Symantec Norton Personal Firewall for Macintosh 3.1 Symantec Norton Personal Firewall for Macintosh 3.0 Symantec Norton Internet Security for Macintosh 3.0 Symantec Norton Antivirus for Macintosh 10.9.1 Symantec Norton Antivirus for Macintosh 10.0.1 Symantec Norton Antivirus for Macintosh 10.0 .0 Symantec Norton Antivirus for Macintosh 9.0.3 Symantec Norton Antivirus for Macintosh 9.0.2 Symantec Norton Antivirus for Macintosh 9.0.1 Symantec Norton Antivirus for Macintosh 9.0 .0 Symantec LiveUpdate for Macintosh 3.5 Symantec LiveUpdate for Macintosh 3.0.3 Symantec LiveUpdate for Macintosh 3.0.2 Symantec LiveUpdate for Macintosh 3.0.1 Symantec LiveUpdate for Macintosh 3.0 Symantec AntiVirus for Macintosh 10.0 |
| Not Vulnerable: | |
Discussion
Symantec LiveUpdate for Macintosh Local Privilege Escalation Vulnerability
Symantec LiveUpdate for Macintosh is prone to a local privilege-escalation vulnerability. This issue is due to the application's failure to properly use the PATH environment variable in some of its components.
A successful exploit allows local attackers to gain superuser privileges, leading to a complete compromise of the affected computer.
Symantec LiveUpdate for Macintosh is prone to a local privilege-escalation vulnerability. This issue is due to the application's failure to properly use the PATH environment variable in some of its components.
A successful exploit allows local attackers to gain superuser privileges, leading to a complete compromise of the affected computer.
Exploit / POC
Symantec LiveUpdate for Macintosh Local Privilege Escalation Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Symantec LiveUpdate for Macintosh Local Privilege Escalation Vulnerability
Solution:
Symantec has released an advisory to address this issue. Please see the references for more information.
Fixes have been released as part of Symantec LiveUpdate. See the referenced advisory for instructions on manually running LiveUpdate.
Solution:
Symantec has released an advisory to address this issue. Please see the references for more information.
Fixes have been released as part of Symantec LiveUpdate. See the referenced advisory for instructions on manually running LiveUpdate.
References
Symantec LiveUpdate for Macintosh Local Privilege Escalation Vulnerability
References:
References: