7.2
CVSSv2

CVE-2006-4392

Published: 03/10/2006 Updated: 17/10/2018
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 730
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The Mach kernel, as used in operating systems including (1) Mac OS X 10.4 up to and including 10.4.7 and (2) OpenStep prior to 4.2, allows local users to gain privileges via a parent process that forces an exception in a setuid child and uses Mach exception ports to modify the child's thread context and task address space in a way that causes the child to call a parent-controlled function.

Vulnerable Product Search on Vulmon Subscribe to Product

apple mac os x 10.4

apple mac os x 10.4.7

next openstep 4.1

apple mac os x 10.4.3

apple mac os x 10.4.4

apple mac os x 10.4.1

apple mac os x 10.4.2

apple mac os x 10.4.5

apple mac os x 10.4.6

Exploits

Mac OS X versions 1047 and below Mach Exception handling local exploit ...
/* excploitc - 28 Nov 2005 - xmath@mathleidenunivnl * * Exploitable Mach Exception Handling * * Affected: Mac OS X 1046 (darwin 860) and older * * When a process executes a setuid executable, all existing rights to the * task port are invalidated, to make sure unauthorized processes do not * retain control of the process Exception ...
/* excploitc - 28 Nov 2005 - xmath@mathleidenunivnl * * Exploitable Mach Exception Handling * * Affected: Mac OS X 1046 (darwin 860) and older * * When a process executes a setuid executable, all existing rights to the * task port are invalidated, to make sure unauthorized processes do not * retain control of the process Exception ...