Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2003-0877

EPSS 0.07% · P21
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2003-0877

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Mac OS X before 10.3 with core files enabled allows local users to overwrite arbitrary files and read core files via a symlink attack on core files that are created with predictable names in the /cores directory.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Apple Mac OS X Core文件符号链接漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Mac OS X是一款使用在Mac机器上的操作系统,基于BSD系统。 Apple Mac OS X不安全生成core文件,本地攻击者可以利用这个漏洞通过符号链接进行权限提升攻击。 Core文件的建立在Mac OS X中默认是关闭的,如果在系统中允许生成core文件,属主为ROOT的进程会写core文件到/cores目录中,core文件的名称为core.PID(*),此文件属主为ROOT,设置权限是0400。由于/cores木默认全局可写,core文件名可预测,攻击者可以通过建立符号链接,指向系统重要文件,
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2003-0877

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2003-0877

登录查看更多情报信息。

Same Patch Batch · n/a · 2003-10-30 · 16 CVEs total

CVE-2002-1570Net-SNMP snmpnetstat远程基于堆溢出漏洞
CVE-2003-0542Apache Web Server 缓冲区错误漏洞
CVE-2003-0683SGI IRIX NFS Exportfs通用条目未授权访问漏洞
CVE-2003-0789Apache Web Server 安全漏洞
CVE-2003-0855Pan Long Author Address服务拒绝漏洞
CVE-2003-0871Apple Mac OS X 10.3未明Apple Quicktime Java漏洞
CVE-2003-0876Apple Mac OS X不安全文件权限漏洞
CVE-2003-0878Mac OS X slpd daemon漏洞
CVE-2003-0880Mac OS X漏洞
CVE-2003-0881Mac OS X 权限泄露漏洞
CVE-2003-0882Mac OS X漏洞
CVE-2003-0883Mac OS X漏洞
CVE-2003-0895MacOS X超长Argv值内核缓冲区溢出漏洞
CVE-2003-0899thttpd defang远程缓冲区溢出漏洞
CVE-2003-0901PostgreSQL To_Ascii()缓冲区溢出漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2003-0877

No comments yet


Leave a comment