OSVDB ID: 35340

Title: Cisco Trust Agent on Mac OS X User Notification Authentication Bypass

Info

Disclosure

Jun 11, 2007

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Unknown

Description

Trust Agent for Mac OS X contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is triggered when the agent delivers a message to a login screen, or over the password prompt to exit the screensaver, through which an unauthenticated user can access System Preferences as the root user. This flaw may lead to a loss of integrity.

Classification

Location: Local Access Required
Attack Type: Other
Impact: Loss of Integrity
Exploit: Exploit Public
OSVDB: Security Software

Solution

Upgrade to version 2.1.104.0 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.

Products

Cisco Systems, Inc.

Trust Agent on Mac OS X

2.1.103.0

References

Credit

  • Adam Blake - adblakedeloitte.co.uk - Deloitte UK


Direct URL: http://osvdb.org/35340