Apple MacOS X DHCP Response Root Compromise Vulnerability
BID:9110
Info
Apple MacOS X DHCP Response Root Compromise Vulnerability
| Bugtraq ID: | 9110 |
| Class: | Configuration Error |
| CVE: |
CVE-2003-1009 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 26 2003 12:00AM |
| Updated: | Jul 12 2009 12:56AM |
| Credit: | The disclosure of this issue has been credited to William Carrel. |
| Vulnerable: |
Apple Mac OS X Server 10.3.2 Apple Mac OS X Server 10.3.1 Apple Mac OS X Server 10.3 Apple Mac OS X Server 10.2.8 Apple Mac OS X Server 10.2.7 Apple Mac OS X Server 10.2.6 Apple Mac OS X Server 10.2.5 Apple Mac OS X Server 10.2.4 Apple Mac OS X Server 10.2.3 Apple Mac OS X Server 10.2.2 Apple Mac OS X Server 10.2.1 Apple Mac OS X Server 10.2 Apple Mac OS X 10.3.2 Apple Mac OS X 10.2.8 Apple Mac OS X 10.0.3 Apple Mac OS X 10.0.2 |
| Not Vulnerable: | |
Discussion
Apple MacOS X DHCP Response Root Compromise Vulnerability
It has been reported that Apple MacOS X may be prone to a vulnerability that may allow an attacker to gain root access to a vulnerable system via DHCP responses.
It has been reported that systems running MacOS X attempt to negotiate DHCP on all available interfaces. If a network is not found, and that system is implementing the use of wireless connectivity, then that system will attempt to connect to any network in order to obtain an address. The system will also attempt to connect to an LDAP or NetInfo server on the network by using DHCP provided fields. The vulnerable host is reported to implicitly trust the server for correct information. It has also been reported that an attacker may set up a malicious server and thereby be able to login to a vulnerable system using any login name and a user id (uid) of 0 in response to DHCP lease requests.
It has been reported that Apple MacOS X may be prone to a vulnerability that may allow an attacker to gain root access to a vulnerable system via DHCP responses.
It has been reported that systems running MacOS X attempt to negotiate DHCP on all available interfaces. If a network is not found, and that system is implementing the use of wireless connectivity, then that system will attempt to connect to any network in order to obtain an address. The system will also attempt to connect to an LDAP or NetInfo server on the network by using DHCP provided fields. The vulnerable host is reported to implicitly trust the server for correct information. It has also been reported that an attacker may set up a malicious server and thereby be able to login to a vulnerable system using any login name and a user id (uid) of 0 in response to DHCP lease requests.
Exploit / POC
Apple MacOS X DHCP Response Root Compromise Vulnerability
Proof of concept guidelines are available from the following web site:
http://www.carrel.org/dhcp-vuln.html
Proof of concept guidelines are available from the following web site:
http://www.carrel.org/dhcp-vuln.html
Solution / Fix
References
Apple MacOS X DHCP Response Root Compromise Vulnerability
References:
References:
- Mac OS X Homepage (Apple)
- Mac OS X Security Advisory (Carrel.org)