CVE Vulnerabilities

CVE-2007-0752

Published: May 24, 2007 | Modified: Jul 29, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

The PPP daemon (pppd) in Apple Mac OS X 10.4.8 checks ownership of the stdin file descriptor to determine if the invoker has sufficient privileges, which allows local users to load arbitrary plugins and gain root privileges by bypassing this check.

Affected Software

Name Vendor Start Version End Version
Mac_os_x Apple 10.4.8 (including) 10.4.8 (including)
Mac_os_x_server Apple 10.4.8 (including) 10.4.8 (including)

References