search menu icon-carat-right cmu-wordmark

CERT Coordination Center

Apple Mac OS X Apple Type Services server fails to securely create error log files

Vulnerability Note VU#323424

Original Release Date: 2006-11-30 | Last Revised: 2006-12-20

Overview

The Apple Mac OS X Apple Type Services server insecurely creates error log files, which may allow a local attacker to overwrite or create files with system privileges.

Description

Apple Mac OS X Apple Type Services server fails to securely create error log files. A local attacker may be able to overwrite or create files with system privileges.

Impact

This vulnerability may allow a local attacker to overwrite or create files with system privileges.

Solution

Apply Apple updates

Apple has addressed this issue with Apple Security Update 2006-007.

Vendor Information

323424
 

CVSS Metrics

Group Score Vector
Base
Temporal
Environmental

References

Acknowledgements

This vulnerability was reported in Apple Security Update 2006-007.

This document was written by Katie Steiner.

Other Information

CVE IDs: CVE-2006-4396
Severity Metric: 3.51
Date Public: 2006-11-28
Date First Published: 2006-11-30
Date Last Updated: 2006-12-20 15:37 UTC
Document Revision: 14

Sponsored by CISA.