CVE-2007-0752
The PPP daemon (pppd) in Apple Mac OS X 10.4.8 checks ownership of the stdin file descriptor to determine if the invoker has sufficient privileges, which...
- 公開済み
- 2007/05/24
- 更新済み
- 2024/08/07
- CNA の割り当て
- mitre
- 観察された証拠
- 2007/05/25
プライマリ CVSS
nvd · CVSS 2.0
AV:L/AC:L/Au:N/C:C/I:C/A:C低 · 今後 30 日間
- パーセンタイル
- 52.1%
- モデルの日付
- 2026/09/21
EPSS は統計的な推定値であり、確実性や影響の尺度ではありません。 CVSS、KEV ステータス、暴露、環境と組み合わせます。
概要
The PPP daemon (pppd) in Apple Mac OS X 10.4.8 checks ownership of the stdin file descriptor to determine if the invoker has sufficient privileges, which allows local users to load arbitrary plugins and gain root privileges by bypassing this check. Apple Mac OS X 10.4.8 の PPP デーモン (pppd) は、呼び出し元が十分な権限を持っているかを判断するために標準入力ファイル記述子の所有権をチェックします。このため、ローカルユーザーはこのチェックをバイパスすることで任意のプラグインをロードし、root 権限を取得できる可能性があります。
ソース
1qaaz · osx · 2007/05/25
責任ある使用
脆弱性情報は、自分が所有しているシステム、またはテストを許可されているシステムでのみ使用してください。 Kitploit は公開研究メタデータにリンクしており、エクスプロイト コードや悪意のあるペイロードは保存しません。