The IOKit HID interface in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 does not sufficiently limit access to certain controls, which allows local users to gain privileges by using HID device events to read keystrokes from the console.
Link | Tags |
---|---|
http://www.osvdb.org/34855 | vdb entry |
http://secunia.com/advisories/24966 | third party advisory |
http://www.us-cert.gov/cas/techalerts/TA07-072A.html | third party advisory us government resource |
http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html | patch vendor advisory |
http://www.securityfocus.com/bid/22948 | vdb entry |
http://docs.info.apple.com/article.html?artnum=305391 | |
http://docs.info.apple.com/article.html?artnum=305214 | |
http://www.securitytracker.com/id?1017751 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/32973 | vdb entry |
http://www.securitytracker.com/id?1017942 | vdb entry |
http://www.us-cert.gov/cas/techalerts/TA07-109A.html | third party advisory us government resource |
http://www.vupen.com/english/advisories/2007/0930 | vdb entry |
http://lists.apple.com/archives/Security-announce/2007/Apr/msg00001.html | vendor advisory |
http://www.vupen.com/english/advisories/2007/1470 | vdb entry |
http://secunia.com/advisories/24479 | third party advisory |