Vulnerability in Apple Mac OS X (July 24, 2015)
Risk
- Privilege Escalation
Affected Systems
- Mac OS X
Mac OS X versions 10.10.0 to 10.10.4
Summary
A vulnerability has been discovered in Apple Mac OS X. It allows an attacker to achieve privilege escalation.
Solution
Exploitation of this vulnerability is based on the overflow of an environment variable in Mac OS 10.10.x. Indeed, the implicated environment variable allows the system to indicate a file in which to log errors.
The exploitation of this vulnerability therefore allows arbitrary file writing with high privileges and can thus lead to privilege escalation.
This feature is only available from version 10.10 of Mac OS X, so earlier versions are not affected.
Refer to the vendor's security bulletin for obtaining patches (see Documentation section).
Documentation
- OS X 10.10 DYLD_PRINT_TO_FILE Local Privilege Escalation Vulnerability of December 22, 2015 /notice/CERTFR-2015-AVI-355/
- Vendor security bulletin https://support.apple.com/en-us/HT205031
- SUIDGuard kernel extension https://github.com/sektioneins/SUIDGuard
- OS X 10.10 DYLD_PRINT_TO_FILE Local Privilege Escalation Vulnerability https://www.sektioneins.de/en/blog/15-07-07-dyld_print_to_file_lpe.html
How it works
Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.
Questions are cached — you'll always get the same 5 for this article.