Apple Podcast Producer Authentication-Bypass Vulnerability
BID:32870
Info
Apple Podcast Producer Authentication-Bypass Vulnerability
| Bugtraq ID: | 32870 |
| Class: | Access Validation Error |
| CVE: |
CVE-2008-4223 |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 15 2008 12:00AM |
| Updated: | Dec 17 2008 10:41PM |
| Credit: | Apple |
| Vulnerable: |
Apple Mac OS X Server 10.5.5 Apple Mac OS X Server 10.5.4 Apple Mac OS X Server 10.5.3 Apple Mac OS X Server 10.5.2 Apple Mac OS X Server 10.5.1 Apple Mac OS X Server 10.5 |
| Not Vulnerable: |
Apple Mac OS X Server 10.5.6 |
Discussion
Apple Podcast Producer Authentication-Bypass Vulnerability
Podcast Producer is prone to an authentication-bypass vulnerability. An attacker can exploit this issue to gain access to certain administrative functions. This may result in an elevation of privilege and may aid in further attacks.
This issue affects Podcast Producer for Mac OS X Server 10.5 through 10.5.5.
NOTE: This issue was previously covered in BID 32839 (Apple Mac OS X 2008-008 Multiple Security Vulnerabilities), but has been given its own record to better document the issue.
Podcast Producer is prone to an authentication-bypass vulnerability. An attacker can exploit this issue to gain access to certain administrative functions. This may result in an elevation of privilege and may aid in further attacks.
This issue affects Podcast Producer for Mac OS X Server 10.5 through 10.5.5.
NOTE: This issue was previously covered in BID 32839 (Apple Mac OS X 2008-008 Multiple Security Vulnerabilities), but has been given its own record to better document the issue.
Exploit / POC
Apple Podcast Producer Authentication-Bypass Vulnerability
An attacker needs local access to an affected computer to exploit this issue.
An attacker needs local access to an affected computer to exploit this issue.
Solution / Fix
Apple Podcast Producer Authentication-Bypass Vulnerability
Solution:
Vendor updates are available.
Apple Mac OS X Server 10.5
Apple Mac OS X Server 10.5.1
Apple Mac OS X Server 10.5.2
Apple Mac OS X Server 10.5.3
Apple Mac OS X Server 10.5.4
Apple Mac OS X Server 10.5.5
Solution:
Vendor updates are available.
Apple Mac OS X Server 10.5
-
Apple MacOSXServerUpdCombo10.5.6.dmg
http://www.apple.com/support/downloads/
Apple Mac OS X Server 10.5.1
-
Apple MacOSXServerUpdCombo10.5.6.dmg
http://www.apple.com/support/downloads/
Apple Mac OS X Server 10.5.2
-
Apple MacOSXServerUpdCombo10.5.6.dmg
http://www.apple.com/support/downloads/
Apple Mac OS X Server 10.5.3
-
Apple MacOSXServerUpdCombo10.5.6.dmg
http://www.apple.com/support/downloads/
Apple Mac OS X Server 10.5.4
-
Apple MacOSXServerUpdCombo10.5.6.dmg
http://www.apple.com/support/downloads/
Apple Mac OS X Server 10.5.5
-
Apple MacOSXServerUpd10.5.6.dmg
http://www.apple.com/support/downloads/
References
Apple Podcast Producer Authentication-Bypass Vulnerability
References:
References: