CVE-2003-0171: High severity apple mac os x server vulnerability
DirectoryServices in MacOS X trusts the PATH environment variable to locate and execute the touch command, which allows local users to execute arbitrary commands by modifying the PATH to point to a directory containing a malicious touch program.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2003-0171?
CVE-2003-0171 is considered a moderate severity vulnerability due to its potential for local privilege escalation.
How do I fix CVE-2003-0171?
To fix CVE-2003-0171, ensure that the PATH environment variable is not misconfigured and avoid allowing untrusted directories to be included.
What systems are affected by CVE-2003-0171?
CVE-2003-0171 affects various versions of Mac OS X and Mac OS X Server, primarily versions between 10.0 and 10.2.4.
What type of vulnerability is CVE-2003-0171?
CVE-2003-0171 is a local security vulnerability that allows users to execute arbitrary commands by manipulating the PATH variable.
Who can exploit CVE-2003-0171?
CVE-2003-0171 can be exploited by local users who can modify the PATH environment variable to point to malicious executables.