First published: Sat Dec 31 2005(Updated: )
passwd in Directory Services in Mac OS X 10.3.x before 10.3.9 and 10.4.x before 10.4.5 allows local users to create arbitrary world-writable files as root by specifying an alternate file in the password database option.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS and macOS | =10.4.3 | |
Apple iOS and macOS | =10.4.3 | |
Apple iOS and macOS | =10.3.2 | |
Apple iOS and macOS | =10.3.7 | |
Apple iOS and macOS | =10.3.5 | |
Apple iOS and macOS | =10.3.1 | |
Apple iOS and macOS | =10.3.5 | |
Apple iOS and macOS | =10.4.1 | |
Apple iOS and macOS | =10.4.2 | |
Apple iOS and macOS | =10.3.3 | |
Apple iOS and macOS | =10.4.4 | |
Apple iOS and macOS | =10.4.1 | |
Apple iOS and macOS | =10.4.4 | |
Apple iOS and macOS | =10.3.4 | |
Apple iOS and macOS | =10.3.2 | |
Apple iOS and macOS | =10.3.7 | |
Apple iOS and macOS | =10.4 | |
Apple iOS and macOS | =10.4.5 | |
Apple iOS and macOS | =10.3.6 | |
Apple iOS and macOS | =10.3 | |
Apple iOS and macOS | =10.3.8 | |
Apple iOS and macOS | =10.4 | |
Apple iOS and macOS | =10.3.9 | |
Apple iOS and macOS | =10.3.8 | |
Apple iOS and macOS | =10.3.1 | |
Apple iOS and macOS | =10.4.5 | |
Apple iOS and macOS | =10.3.9 | |
Apple iOS and macOS | =10.3.4 | |
Apple iOS and macOS | =10.3.3 | |
Apple iOS and macOS | =10.4.2 | |
Apple iOS and macOS | =10.3 | |
Apple iOS and macOS | =10.3.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-2713 is rated as a moderate severity vulnerability that allows local users to create arbitrary world-writable files as root.
To fix CVE-2005-2713, users should upgrade their Mac OS X to version 10.3.9 or later, or 10.4.5 or later.
CVE-2005-2713 affects macOS versions 10.3.x prior to 10.3.9 and 10.4.x prior to 10.4.5.
CVE-2005-2713 is not remotely exploitable as it requires local user access to be exploited.
If an upgrade is not possible, consider tightening file permissions and implementing user access restrictions to mitigate risks associated with CVE-2005-2713.