Adobe Version Cue (Mac OS X) Lets Local Users Gain Elevated Privileges
|
|
SecurityTracker Alert ID: 1014776
|
|
SecurityTracker URL: http://securitytracker.com/id?1014776
|
|
CVE Reference: CVE-2005-1842
, CVE-2005-1843
(Links to External Site)
|
Updated: Jun 8 2008
|
Original Entry Date: Aug 23 2005
|
Impact: Execution of arbitrary code via local system, Modification of system information, Modification of user information, Root access via local system
|
Fix Available: Yes
Vendor Confirmed: Yes
|
Advisory: Adobe Advisory
|
Version(s): 1.0 and 1.0.1
|
Description: A vulnerability was reported in Adobe Version Cue for Mac OS X. A local user can gain elevated privileges on the target system.
Certain internal Version Cue files have special file permissions that can be exploited by a local user to gain system administrator
privileges.
A local user can cause arbitrary libraries to be loaded with elevated privileges [CVE-2005-1843].
A local user
can overwrite arbitrary files with elevated privileges [CVE-2005-1842].
This product is included as a feature of Adobe Creative
Suite 1.0 and 1.3.
|
Impact: A local user can obtain system administrator privileges on the target system.
|
Solution: The vendor has issued a fix, available at:
http://www.adobe.com/support/downloads/detail.jsp?ftpID=2985
|
Vendor URL: www.adobe.com/support/techdocs/327129.html (Links to External Site)
|
Cause: Access control error
|
Underlying OS: UNIX (OS X)
|
|
Message History:
None.
|
Source Message Contents
|
Date: Tue, 23 Aug 2005 02:49:39 -0400
Subject: http://www.adobe.com/support/techdocs/327129.html
|
> Advisory: Adobe Version Cue 1.x for Mac OS X System Privilege Escalation
> Products: Adobe Version Cue 1.0 and 1.0.1 (Included as a feature of Adobe Creative
> Suite 1.0 and 1.3.)
>
> Platform: All supported versions of Mac OS X
> CAN-2005-1842: VCNative Arbitrary File Overwriting
>
> CAN-2005-1843: VCNative Arbitrary Library Loading
|
|