First published: Mon Mar 03 2003(Updated: )
TruBlueEnvironment for MacOS 10.2.3 and earlier allows local users to overwrite or create arbitrary files and gain root privileges by setting a certain environment variable that is used to write debugging information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
macOS Yosemite | =10.2.1 | |
macOS Yosemite | =10.2.2 | |
macOS Yosemite | =10.2.3 | |
macOS Yosemite | =10.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-0088 has a medium severity level due to potential root privilege escalation.
To fix CVE-2003-0088, update your TruBlueEnvironment or macOS to a version later than 10.2.3 that addresses this vulnerability.
CVE-2003-0088 affects TruBlueEnvironment on macOS versions 10.2 and earlier, specifically 10.2.1, 10.2.2, and 10.2.3.
CVE-2003-0088 allows local users to overwrite or create arbitrary files, potentially leading to unauthorized root access.
Exploiting CVE-2003-0088 is relatively straightforward for local users who can manipulate the environment variable responsible for file writing.