First published: Sat Jan 29 2005(Updated: )
The "at" commands on Mac OS X 10.3.7 and earlier do not properly drop privileges, which allows local users to (1) delete arbitrary files via atrm, (2) execute arbitrary programs via the -f argument to batch, or (3) read arbitrary files via the -f argument to batch, which generates a job file that is readable by the local user.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
macOS Yosemite | =10.3.4 | |
macOS Yosemite | =10.3.7 | |
Apple Mac OS X Server | =10.3.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-0125 has a medium severity rating due to its potential for local privilege escalation.
To fix CVE-2005-0125, upgrade to Mac OS X 10.4 or later where the privilege issue is resolved.
CVE-2005-0125 affects Mac OS X versions 10.3.4 and 10.3.7, including Mac OS X Server 10.3.7.
An attacker can delete arbitrary files, execute arbitrary programs, or read sensitive files locally due to privilege escalation.
CVE-2005-0125 was reported in January 2005.