vendor:
Not provided
by:
v9@fakehalo.us (fakehalo/realhalo)
7.5
CVSS
HIGH
Local root exploit
Not provided
CWE
Product Name: Not provided
Affected Version From: Not provided
Affected Version To: Not provided
Patch Exists: NO
Related CWE: Not provided
CPE: Not provided
Platforms Tested: MacOS X
2005
MacOS X[CF_CHARSET_PATH]: local root exploit.
This is a local root exploit for MacOS X that exploits a vulnerability in the CF_CHARSET_PATH. It allows an attacker to gain root privileges on the system. The exploit takes advantage of a buffer overflow in the /usr/bin/su binary. The user must press ENTER at the "Password: " prompt for the exploit to work.
Mitigation:
Patch or update the affected system to a non-vulnerable version. Limit access to the vulnerable binary.