Overview
CrashReporter contains a privilege escalation vulnerability that may allow authenticated users to run commands as root.
Description
CrashReporter is a debugging facility in Apple OS X that logs information program crashes. CrashReporter contains a privilege escalation vulnerability. This vulnerability occurs because a user which has admin privileges can cause CrashReporter's log files to be written to arbitrary files as root. This vulnerability may result in the execution of commands with root privileges. |
Impact
An authenticated attacker may be able to issue arbitrary commands with root privileges or overwrite arbitrary files. |
Solution
Upgrade |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
This issue was made public on the Month of Apple Bugs website.
This document was written by Ryan Giobbi.
Other Information
CVE IDs: | CVE-2007-0467 |
Severity Metric: | 0.35 |
Date Public: | 2007-01-28 |
Date First Published: | 2007-03-13 |
Date Last Updated: | 2007-03-13 21:50 UTC |
Document Revision: | 18 |