>> Apple Mac OS X Multiple Denial of Service and Privilege Escalation Vulnerabilities
Title : Apple Mac OS X Multiple Denial of Service and Privilege Escalation Vulnerabilities VUPEN ID : VUPEN/ADV-2007-0074 CVE ID : CVE-2007-0022 - CVE-2007-0117 - CVE-2007-0467
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-01-08
Technical Description
Multiple vulnerabilities have been identified in Apple Mac OS X, which could be exploited by attackers to cause a denial of service or obtain elevated privileges.
The first issue is due to an error in the DiskManagement framework when processing BOM files, which could be exploited by malicious users to execute arbitrary commands with elevated privileges via the "diskutil" tool.
The second issue is due to an error in "writeconfig" that does not validate the "PATH" environment variable when starting services via "/sbin/service", which could be exploited by malicious users to gain elevated privileges.
The third vulnerability is due to an error in "crashreporterd" that trusts symlinks when generating crash reports, which could be exploited by malicious users in the admin group to obtain "root" privileges.