4.6
CVSSv2

CVE-2005-1843

Published: 24/08/2005 Updated: 05/09/2008
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 465
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

VCNative for Adobe Version Cue 1.0 and 1.0.1, as used in Creative Suite 1.0 and 1.3, and when running on Mac OS X with Version Cue Workspace, allows local users to load arbitrary libraries and execute arbitrary code via the -lib command line argument.

Vulnerable Product Search on Vulmon Subscribe to Product

adobe version cue 1.0.1

adobe version cue 1.0

Exploits

/*[ Adobe Version Cue VCNative[OSX]: local root exploit (dyld) ] * * by: vade79/v9 v9@fakehalous (fakehalo/realhalo) * * Adobe Version Cue's VCNative program allows un-privileged * local users to load arbitrary libraries("bundles") while * running setuid root this is done via the "-lib" * command-line option * * note: VCNative must conn ...