|
|
|
![]() |
Vulnerability Note VU#312424Apple AFP Client privilege escalation vulnerabilityOverviewThe Apple File Protocol (AFP) Client fails to properly clean its environment before executing commands. This vulnerability may allow a local attacker execute commands with elevated privileges.I. DescriptionThe Apple File Protocol service allows Apple Mac OS clients to access files remotely from a server. According to Apple Security Update 2007-004:Under certain circumstances, AFP Client may execute commands without properly cleaning the environment. This may allow a local user to create files or execute commands with system II. ImpactA local attacker may be able to execute commands with elevated privileges.III. SolutionApply Updates from AppleApple has addressed this vulnerability with the updates included in Apple Security Update 2007-004.
References
This vulnerability was reported in Apple Security Update 2007-004. This document was written by Jeff Gennari.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||