CVE-2003-1009

Apple Mac OS X <10.4 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Directory Services in Apple Mac OS X 10.0.2, 10.0.3, 10.2.8, 10.3.2 and Apple Mac OS X Server 10.2 through 10.3.2 accepts authentication server information from unknown LDAP or NetInfo sources as provided by a malicious DHCP server, which allows remote attackers to gain privileges.

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/13874
Various Sources x_refsource_misc
http://www.carrel.org/dhcp-vuln.html
Vendor Advisory x_refsource_misc
http://docs.info.apple.com/article.html?artnum=32478
Patch, Vendor Advisory x_refsource_confirm
http://docs.info.apple.com/article.html?artnum=61798
Exploit, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/9110

Scores

EPSS 0.0457
EPSS Percentile 90.7%

Details

Status published
Products (16)
apple/mac_os_x 10.0.2
apple/mac_os_x 10.0.3
apple/mac_os_x 10.2.8
apple/mac_os_x 10.3.2
apple/mac_os_x_server 10.2
apple/mac_os_x_server 10.2.1
apple/mac_os_x_server 10.2.2
apple/mac_os_x_server 10.2.3
apple/mac_os_x_server 10.2.4
apple/mac_os_x_server 10.2.5
... and 6 more
Published Mar 29, 2004
Tracked Since Feb 18, 2026