Apple Mac OS X cd9660.util utility buffer overflow
| macos-cd9660-bo (13995) |
Description:
Apple Mac OS X is vulnerable to a buffer overflow in the cd9660.util utility, caused by improper validation of user-supplied input. The utility is installed suid root. A local attacker could exploit this vulnerability to overflow a buffer and execute arbitrary code on the system.
Platforms Affected:
- Apple, Mac OS X 10.0
- Apple, Mac OS X 10.0.4
- Apple, Mac OS X 10.1
- Apple, Mac OS X 10.1.1
- Apple, Mac OS X 10.1.2
- Apple, Mac OS X 10.1.3
- Apple, Mac OS X 10.1.4
- Apple, Mac OS X 10.1.5
- Apple, Mac OS X 10.2
- Apple, Mac OS X 10.2.1
- Apple, Mac OS X 10.2.2
- Apple, Mac OS X 10.2.3
- Apple, Mac OS X 10.2.4
- Apple, Mac OS X 10.2.5
- Apple, Mac OS X 10.2.6
- Apple, Mac OS X 10.2.7
- Apple, Mac OS X 10.2.8
- Apple, Mac OS X 10.3
- Apple, Mac OS X 10.3.1
- Apple, Mac OS X 10.3.2
- Apple, Mac OS X Server 10.0
- Apple, Mac OS X Server 10.0.1
- Apple, Mac OS X Server 10.0.2
- Apple, Mac OS X Server 10.0.3
- Apple, Mac OS X Server 10.2
- Apple, Mac OS X Server 10.2.1
- Apple, Mac OS X Server 10.2.2
- Apple, Mac OS X Server 10.2.3
- Apple, Mac OS X Server 10.2.4
- Apple, Mac OS X Server 10.2.5
- Apple, Mac OS X Server 10.2.6
- Apple, Mac OS X Server 10.2.7
- Apple, Mac OS X Server 10.2.8
- Apple, Mac OS X Server 10.3
- Apple, Mac OS X Server 10.3.1
- Apple, Mac OS X Server 10.3.2
Remedy:
Upgrade to Security Update 2003-12-19 or later, as recommended in Apple Knowledge Base article 120291. See References.
Consequences:
Gain Privileges
References:
- AppleCare Knowledge Base Document 120291, Security Update 2003-12-19 (Jaguar) : Information and Download at http://docs.info.apple.com/article.html?artnum=120291.
- AppleCare Knowledge Base Document 61798, Apple Security Updates at http://docs.info.apple.com/article.html?artnum=61798.
- BugTraq Mailing List, Mon Dec 15 2003 - 13:54:02 CST , Buffer overflow/privilege escalation in MacOS X at http://archives.neohapsis.com/archives/bugtraq/2003-12/0224.html.
- BugTraq Mailing List, Mon Dec 15 2003 - 16:48:21 CST, Re: Buffer overflow/privilege escalation in MacOS X at http://archives.neohapsis.com/archives/bugtraq/2003-12/0234.html.
- BID-9228: MacOSX CD9660.Util Probe For Mounting Argument Local Buffer Overflow Vulnerability
- BID-923: Microsoft Internet Explorer Security Zone Settings Lag Vulnerability
- CVE-2003-1006: Buffer overflow in cd9660.util in Apple Mac OS X 10.0 through 10.3.2 and Apple Mac OS X Server 10.0 through 10.3.2 may allow local users to execute arbitrary code via a long command line parameter.
- US-CERT VU#878526: Apple Mac OS X cd9660.util buffer overflow
Reported:
Dec 15, 2003
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
For corrections or additions please email xforce@iss.net
