Apple Mac OS X pax Archive Utility Remote Code Execution Vulnerability
BID:28365
Info
Apple Mac OS X pax Archive Utility Remote Code Execution Vulnerability
| Bugtraq ID: | 28365 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-0992 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 18 2008 12:00AM |
| Updated: | Mar 20 2008 10:30PM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
Apple Mac OS X Server 10.5.2 Apple Mac OS X Server 10.5.1 Apple Mac OS X Server 10.5 Apple Mac OS X 10.5.2 Apple Mac OS X 10.5.1 Apple Mac OS X 10.5 |
| Not Vulnerable: | |
Discussion
Apple Mac OS X pax Archive Utility Remote Code Execution Vulnerability
Apple Mac OS X is prone to a remote code-execution vulnerability because the software fails to adequately validate user-supplied data.
Successfully exploiting this issue will allow attackers to execute arbitrary code with the privileges of the currently logged-in user. This will facilitate the remote compromise of affected computers.
NOTE: This vulnerability was previously covered in BID 28304 (Apple Mac OS X 2008-002 Multiple Security Vulnerabilities), but has been given its own record to better document the issue.
Apple Mac OS X is prone to a remote code-execution vulnerability because the software fails to adequately validate user-supplied data.
Successfully exploiting this issue will allow attackers to execute arbitrary code with the privileges of the currently logged-in user. This will facilitate the remote compromise of affected computers.
NOTE: This vulnerability was previously covered in BID 28304 (Apple Mac OS X 2008-002 Multiple Security Vulnerabilities), but has been given its own record to better document the issue.
Exploit / POC
Apple Mac OS X pax Archive Utility Remote Code Execution Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Apple Mac OS X pax Archive Utility Remote Code Execution Vulnerability
Solution:
Vendor fixes are available. Please see the referenced advisory for more information.
Apple Mac OS X 10.5.2
Apple Mac OS X Server 10.5.2
Solution:
Vendor fixes are available. Please see the referenced advisory for more information.
Apple Mac OS X 10.5.2
-
Apple SecUpd2008-002.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=18157&cat= 57&platform=osx&method=sa/SecUpd2008-002.dmg
Apple Mac OS X Server 10.5.2
References
Apple Mac OS X pax Archive Utility Remote Code Execution Vulnerability
References:
References: