Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Apple MacOS Classic TruBlueEnvironment Environment Variable Privilege Escalation Vulnerability

There is a vulnerability in the Apple MacOS Classic emulator for MacOS X that may lead to elevation of privileges. This issue exists in TruBlueEnvironment, which is included in the emulator.

It has been reported that an environment variable may be changed to cause arbitrary local files to be overwritten or created. The environment variable is used to define a location to output debugging information to a file. Exploitation of this issue may enable a malicious local user to gain elevated privileges by causing malicious files to be run through a facility such as cron. Overwriting critical system files may also cause a denial of service.







 

Privacy Statement
Copyright 2008, SecurityFocus