First published: Fri Dec 31 2004(Updated: )
The Macromedia installers and e-licensing client on Mac OS X, as used for Macromedia Contribute 2, Director, Dreamweaver, Fireworks, Flash, and Studio, install the AuthenticationService setuid and writable by other users, which allows local users to gain privileges by modifying the program.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Macromedia Contribute | =2.0 | |
Macromedia Studio | =2004 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-2335 is considered a high severity vulnerability due to its potential for privilege escalation by local users.
To fix CVE-2004-2335, ensure that the AuthenticationService is not setuid and is not writable by other users.
CVE-2004-2335 affects Macromedia Contribute 2 and Macromedia Studio 2004.
CVE-2004-2335 can allow local users to gain unauthorized privileges, compromising system security.
CVE-2004-2335 was discovered in the year 2004.