The remote_cmds component in Apple Mac OS X 10.4 through 10.4.10 contains a symbolic link from the tftpboot private directory to the root directory, which allows tftpd users to escape the private directory and access arbitrary files.
Weaknesses in this category are typically introduced during the configuration of the software.
Link | Tags |
---|---|
http://securitytracker.com/id?1018950 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/38471 | vdb entry |
http://www.securityfocus.com/bid/26444 | vdb entry |
http://lists.apple.com/archives/security-announce/2007/Nov/msg00002.html | patch vendor advisory |
http://docs.info.apple.com/article.html?artnum=307041 | |
http://www.vupen.com/english/advisories/2007/3868 | vdb entry |
http://secunia.com/advisories/27643 | third party advisory vendor advisory |
http://www.us-cert.gov/cas/techalerts/TA07-319A.html | third party advisory us government resource |