Unsanity Application Enhancer (APE) 2.0.2 installs with insecure permissions for the (1) ApplicationEnhancer binary and the (2) /Library/Frameworks/ApplicationEnhancer.framework directory, which allows local users to gain privileges by modifying or replacing the binary or library files.
Link | Tags |
---|---|
http://projects.info-pull.com/moab/MOAB-08-01-2007.html | exploit |
http://landonf.bikemonkey.org/code/macosx/MOAB_Day_8.20070109002959.18582.timor.html | vendor advisory |
http://osvdb.org/32661 | vdb entry |
http://www.securityfocus.com/bid/21951 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/31349 | vdb entry |
http://secunia.com/advisories/23649 | third party advisory |