CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer
image Vulnerabilities: - File overwrite in Mac OS X - image
Cyber Security
Memory. . . is the diary that we all carry about with us.
Oscar Wilde (1856-1900); Irish playwright, novelist.
- File overwrite in Mac OS X -
Oxygen3 24h-365d, by Panda Software (http://www.pandasoftware.com)

Madrid, 29 October 2003 - @stake has reported - at
www.atstake.com/research/advisories/2003/a102803-1.txt - that a
vulnerability has been discovered that affects the operating systems Mac OS
X 10.2.8 and earlier. This vulnerability is fixed in Mac OS X 10.3.



This security flaw occurs in systems running with core files enabled.
Through this vulnerability an attacker with interactive shell access could
overwrite files and read core files created by root processes. This could
result in the loss of confidential data.

Core file creation is disabled by default in Mac OS X, but if it is enabled,
root processes generate them in the /cores directory. The vulnerability lies
in the fact that everybody has write permissions to this directory and that
files are created under an easily predictable name. As a result, an attacker
could generate symbolic links in this directory that point to any other file
in the file system.

NOTE: The address above may not show up on your screen as a single line.
This would prevent you from using the link to access the web page. If this
happens, just use the 'cut' and 'paste' options to join the pieces of the
URL.

------------------------------------------------------------

The 5 viruses most frequently detected by Panda ActiveScan, Panda Software's
free online scanner: 1) Bugbear.B; 2) Blaster; 3) Parite.B; 4) Gibe.C; 5)
Klez.I.
Posted on Wednesday, 29 October 2003 @ 19:17:57 UTC by phoenix22 (830 reads)
[ Trackback ]
image

"Vulnerabilities: - File overwrite in Mac OS X -" | Login/Create an Account | 0 comments
Threshold
The comments are owned by the poster. We aren't responsible for their content.

No Comments Allowed for Anonymous, please register
 
Login
spacer
Nickname

Password

Security Code: Type Security Code: Usage signifies AUP acceptance
· New User? · Click here to create a registered account.
block bottom
Related Links
spacer
· del.icio.us!
· digg it!
· reddit!
· TrackBack (0)
· HotScripts
· W3 Consortium
· More about Cyber Security
· News by phoenix22


Most read story about Cyber Security:
Booby Trapped software!

block bottom
Article Rating
spacer
Average Score: 0
Votes: 0

Please take a second and vote for this article:

Bad
Regular
Good
Very Good
Excellent


block bottom
Options
spacer

Printer Friendly Page  Printer Friendly Page

block bottom
spacer spacer