Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2005-2748 | First vendor Publication | 2005-10-25 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:L/AC:L/Au:N/C:N/I:P/A:N) | |||
---|---|---|---|
Cvss Base Score | 2.1 | Attack Range | Local |
Cvss Impact Score | 2.9 | Attack Complexity | Low |
Cvss Expoit Score | 3.9 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
The malloc function in the libSystem library in Apple Mac OS X 10.3.9 and 10.4.2 allows local users to overwrite arbitrary files by setting the MallocLogFile environment variable to the target file before running a setuid application. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2748 |
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Os | 2 | |
Os | 2 |
OpenVAS Exploits
Date | Description |
---|---|
2009-11-17 | Name : Mac OS X Version File : nvt/macosx_version.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
19706 | Apple Mac OS X Application Memory Debugging MallocLogFile Variable Insecure F... Mac OS X contains a flaw that may allow a malicious local user to create and/or manipulate arbitrary files on the system. The issue is due to malloc reading the MallocLogFile environment variable when running suid executables, modifying any file on the system. It is possible for a user to use a symlink style attack to manipulate arbitrary files, resulting in a loss of integrity. |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2005-09-23 | Name : The remote operating system is missing a vendor-supplied patch. File : macosx_SecUpd2005-008.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:21:47 |
|
2024-11-28 12:07:22 |
|
2021-05-04 12:03:09 |
|
2021-04-22 01:03:25 |
|
2020-05-23 00:16:47 |
|
2016-04-26 13:46:25 |
|
2014-02-17 10:32:40 |
|
2013-05-11 11:30:46 |
|