Vulnerability Note VU#315856
Apple Mac OS X UserNotificationCenter privilege escalation vulnerability
OverviewApple's UserNotificationCenter contains a vulnerability that may allow local users to gain elevated privileges.
I. DescriptionThe Apple UserNotificationCenter contains a privilege escalation vulnerability.
This vulnerability occurs because the Apple UserNotificationCenter runs with elevated privileges while operating on input submitted by users with normal privileges.
II. ImpactA user with valid login credentials may be able to run commands or modify system files with elevated privileges.
III. SolutionApply an update
This issue is addressed in Apple Security Update 2007-002.
Systems Affected
References
http://docs.info.apple.com/article.html?artnum=305102
http://developer.apple.com/documentation/CoreFoundation/Reference/CFUserNotificationRef/Reference/reference.html
http://projects.info-pull.com/moab/MOAB-22-01-2007.html
http://www.cocoadev.com/index.pl?InputManager
http://secunia.com/advisories/23846/
http://www.securityfocus.com/bid/22188
http://secunia.com/advisories/24198/
Credit
LMH published this vulnerability on the Month of Apple Bugs website.
This document was written by Ryan Giobbi.
Other Information
| Date Public: | 2007-01-23 |
| Date First Published: | 2007-02-19 |
| Date Last Updated: | 2007-02-19 |
| CERT Advisory: | |
| CVE-ID(s): | CVE-2007-0023 |
| NVD-ID(s): | CVE-2007-0023 |
| US-CERT Technical Alerts: | |
| Metric: | 1.49 |
| Document Revision: | 23 |
If you have feedback, comments, or additional information about this vulnerability, please send us
email.
|