lists.apple.comConfirmation
http://lists.apple.com/mhonarc/security-announce/msg00028.html CVE-2003-0171
Apple Mac OSX 10.2.4 - DirectoryService 'PATH' Local Privilege Escalation
Record summary
CVE-2003-0171 has a selected CVSS score of 7.2; EIP currently links 1 catalogued exploit.
Description
DirectoryServices in MacOS X trusts the PATH environment variable to locate and execute the touch command, which allows local users to execute arbitrary commands by modifying the PATH to point to a directory containing a malicious touch program.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBApple Mac OSX 10.2.4 - DirectoryService 'PATH' Local Privilege EscalationExploitDB exploitby Neeko OniNot analyzed1 file
References
3A041003-1Vendor advisory
http://www.atstake.com/research/advisories/2003/a041003-1.txt nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2003-0171