Apple MacOS Classic TruBlueEnvironment Environment Variable Privilege Escalation Vulnerability
BID:6859
Info
Apple MacOS Classic TruBlueEnvironment Environment Variable Privilege Escalation Vulnerability
| Bugtraq ID: | 6859 |
| Class: | Design Error |
| CVE: |
CVE-2003-0088 |
| Remote: | No |
| Local: | Yes |
| Published: | Feb 14 2003 12:00AM |
| Updated: | Jul 11 2009 08:06PM |
| Credit: | Discovery of this issue is credited to Dave G. from @stake. |
| Vulnerable: |
Apple Mac OS X Server 10.2.3 Apple Mac OS X Server 10.2.2 Apple Mac OS X Server 10.2.1 Apple Mac OS X Server 10.2 Apple Mac OS X 10.2.3 Apple Mac OS X 10.2.2 Apple Mac OS X 10.2.1 Apple Mac OS X 10.2 |
| Not Vulnerable: |
Apple Mac OS X Server 10.2.4 Apple Mac OS X 10.2.4 |
Discussion
Apple MacOS Classic TruBlueEnvironment Environment Variable Privilege Escalation Vulnerability
There is a vulnerability in the Apple MacOS Classic emulator for MacOS X that may lead to elevation of privileges. This issue exists in TruBlueEnvironment, which is included in the emulator.
It has been reported that an environment variable may be changed to cause arbitrary local files to be overwritten or created. The environment variable is used to define a location to output debugging information to a file. Exploitation of this issue may enable a malicious local user to gain elevated privileges by causing malicious files to be run through a facility such as cron. Overwriting critical system files may also cause a denial of service.
There is a vulnerability in the Apple MacOS Classic emulator for MacOS X that may lead to elevation of privileges. This issue exists in TruBlueEnvironment, which is included in the emulator.
It has been reported that an environment variable may be changed to cause arbitrary local files to be overwritten or created. The environment variable is used to define a location to output debugging information to a file. Exploitation of this issue may enable a malicious local user to gain elevated privileges by causing malicious files to be run through a facility such as cron. Overwriting critical system files may also cause a denial of service.
Exploit / POC
Apple MacOS Classic TruBlueEnvironment Environment Variable Privilege Escalation Vulnerability
There is no exploit required.
There is no exploit required.
References
Apple MacOS Classic TruBlueEnvironment Environment Variable Privilege Escalation Vulnerability
References:
References:
- Security Updates (Apple)