OSVDB ID: 6822

Title: Apple Mac OS X pppd Format String Credential Leak

Info

Disclosure

Feb 23, 2004

Discovery

Unknown

Dates

Exploit

Feb 23, 2004

Solution

Unknown

Description

Mac OS X pppd contains a flaw that may allow a malicious user to read CHAP or PAP authentication credentials in the pppd process. The issue is due to a format string error in a format specifier function "option_error()". By sending a specially crafted command line argument, a local attacker can read arbitrary data in pppd process, including the user's PAP/CHAP authentication credentials. This flaw may lead to a loss of confidentiality.

Classification

Location: Local Access Required, Local / Remote, Context Dependent
Attack Type: Input Manipulation
Impact: Loss of Confidentiality, Loss of Integrity
Exploit: Exploit Public
Disclosure: OSVDB Verified

Solution

Currently, there are no known workarounds or upgrades to correct this issue. However, Apple has released a patch (Security Update 2004-02-23) to address this vulnerability.

Products

Apple Computer, Inc.

pppd

2.4.0

References

Credit

  • Dave G. - davegatstake.com - @stake, Inc.
  • JxT - jtibbssecnetops.com - SNOsoft Research


Direct URL: http://osvdb.org/6822