Apple Mac OS X Server Weblog Access Control List Security Bypass Vulnerability
BID:31718
Info
Apple Mac OS X Server Weblog Access Control List Security Bypass Vulnerability
| Bugtraq ID: | 31718 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2008-4215 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 09 2008 12:00AM |
| Updated: | Oct 15 2008 05:07PM |
| Credit: | This issue was disclosed by the vendor. |
| Vulnerable: |
Apple Mac OS X Server 10.4.11 Apple Mac OS X Server 10.4.11 Apple Mac OS X Server 10.4.10 Apple Mac OS X Server 10.4.9 Apple Mac OS X Server 10.4.8 Apple Mac OS X Server 10.4.7 Apple Mac OS X Server 10.4.6 Apple Mac OS X Server 10.4.5 Apple Mac OS X Server 10.4.4 Apple Mac OS X Server 10.4.3 Apple Mac OS X Server 10.4.2 Apple Mac OS X Server 10.4.1 Apple Mac OS X Server 10.4 |
| Not Vulnerable: | |
Discussion
Apple Mac OS X Server Weblog Access Control List Security Bypass Vulnerability
Apple Mac OS X Server Weblog is prone to a security-bypass vulnerability because it may fail to properly save ACLs (Access Control Lists) in certain cases.
Attackers can exploit this issue to bypass ACL restrictions to perform unauthorized actions with the application.
Mac OS X Server 10.4 through 10.4.11 is vulnerable to this issue.
NOTE: This issue was previously covered in BID 31681 (Apple Mac OS X 2008-007 Multiple Security Vulnerabilities) but has been given its own record to better document this vulnerability.
Apple Mac OS X Server Weblog is prone to a security-bypass vulnerability because it may fail to properly save ACLs (Access Control Lists) in certain cases.
Attackers can exploit this issue to bypass ACL restrictions to perform unauthorized actions with the application.
Mac OS X Server 10.4 through 10.4.11 is vulnerable to this issue.
NOTE: This issue was previously covered in BID 31681 (Apple Mac OS X 2008-007 Multiple Security Vulnerabilities) but has been given its own record to better document this vulnerability.
Exploit / POC
Apple Mac OS X Server Weblog Access Control List Security Bypass Vulnerability
An attacker may exploit this issue using commonly available tools.
An attacker may exploit this issue using commonly available tools.
Solution / Fix
Apple Mac OS X Server Weblog Access Control List Security Bypass Vulnerability
Solution:
The vendor has released fixes; please see the references for more information.
Apple Mac OS X Server 10.4.11
Solution:
The vendor has released fixes; please see the references for more information.
Apple Mac OS X Server 10.4.11
-
Apple SecUpdSrvr2008-007Univ.dmg
(Universal)
http://www.apple.com/support/downloads/securityupdate2008007serveruniv ersal.html
References
Apple Mac OS X Server Weblog Access Control List Security Bypass Vulnerability
References:
References: