Researcher unveils new privilege vulnerability in Apple's Mac OS X

Researcher unveils new privilege vulnerability in Apple's Mac OS X

تاریخ ایجاد

Number: IRCNE2015072576
Date: 2015/07/25

According to “zdnet”, a researcher has disclosed a privilege escalation vulnerability in OS X which is yet to be fixed in the latest release of the operating system.
German researcher Stefan Esser from security audit firm SektionEins disclosed the vulnerability on Tuesday. The security flaw affects OS X 10.10.x and relates to new features added by the iPad and iPhone maker in the newest evolutions of the OS, Yosemite and El Capitan.
The new features exploitable by the vulnerability are based upon the dynamic linker dyld and environment variable DYLD_PRINT_TO_FILE, which enables error logging to an arbitrary file.
"When this variable was added the usual safeguards that are required when adding support for new environment variables to the dynamic linker have not been used. Therefore it is possible to use this new feature even with SUID root binaries," Esser explained.
"This is dangerous, because it allows to open or create arbitrary files owned by the root user anywhere in the file system. Furthermore the opened log file is never closed and therefore its file descriptor is leaked into processes spawned by SUID binaries. This means child processes of SUID root processes can write to arbitrary files owned by the root user anywhere in the filesystem."
This, in turn, allows for privilege escalation and PC hijacking to take place.
The security researcher has released a full technical brief on the vulnerability, a working proof-of-concept (PoC) exploit -- and a warning that executing the code is a danger to systems as it installs a root shell.
Esser says it is "unclear" whether Apple knows about the security flaw or not, as it has already been patched in the first beta versions of OS X El Capitan 10.11, but not in the current release of OS X 10.10.4 or in the current beta of OS X 10.10.5, which has just been released to public beta testers.
In July, Apple released a security update which patched dozens of security flaws in iOS 8.4 and OS X 10.10.4.

برچسب‌ها