CVE-2005-0125: High severity Apple Mac OS X Server vulnerability
The "at" commands on Mac OS X 10.3.7 and earlier do not properly drop privileges, which allows local users to (1) delete arbitrary files via atrm, (2) execute arbitrary programs via the -f argument to batch, or (3) read arbitrary files via the -f argument to batch, which generates a job file that is readable by the local user.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-0125?
CVE-2005-0125 has a medium severity rating due to its potential for local privilege escalation.
How do I fix CVE-2005-0125?
To fix CVE-2005-0125, upgrade to Mac OS X 10.4 or later where the privilege issue is resolved.
What systems are affected by CVE-2005-0125?
CVE-2005-0125 affects Mac OS X versions 10.3.4 and 10.3.7, including Mac OS X Server 10.3.7.
What can attackers do with CVE-2005-0125?
An attacker can delete arbitrary files, execute arbitrary programs, or read sensitive files locally due to privilege escalation.
When was CVE-2005-0125 reported?
CVE-2005-0125 was reported in January 2005.