Apple OS X DYLD_PRINT_TO_FILE Privilege Escalation

Discussion in 'News Aggregator' started by Packet Storm, 24 Jul 2015.

  1. Packet Storm

    Packet Storm Guest

    In Apple OS X 10.10.4 and prior, the DYLD_PRINT_TO_FILE environment variable is used for redirecting logging data to a file instead of stderr. Due to a design error, this feature can be abused by a local attacker to write arbitrary files as root via restricted, SUID-root binaries.

    Continue reading...
     

Share This Page

Loading...