vendor:
Mac OS X
by:
intropy
7.2
CVSS
HIGH
Race Condition
362
CWE
Product Name: Mac OS X
Affected Version From: Mac OS X 10.4
Affected Version To: Mac OS X 10.4
Patch Exists: YES
Related CWE: N/A
CPE: o:apple:mac_os_x:10.4
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Mac
2006
Mac OS X 10.4 launchd race condition exploit
This exploit is used to gain access to a file on Mac OS X 10.4 by exploiting a race condition vulnerability in the launchd service. The exploit uses a .sh script to help with the offsets and a C program to create a symlink to the target file. The exploit then checks if the symlink was successful by checking the UID of the target file.
Mitigation:
The best way to mitigate this vulnerability is to upgrade to a newer version of Mac OS X.