Description: A vulnerability has been discovered in Mac OS X, which can be exploited by malicious, local users to gain escalated privileges.
The problem is that "ARDAgent", which is owned by "root" and has the setuid bit set, can be invoked to execute shell commands via AppleScript (e.g. through "osascript"). This can be exploited to execute arbitrary commands with root privileges.
The vulnerability is confirmed on Mac OS X 10.4 and is also reported in version 10.5.
Provided and/or discovered by: Reported in the Macshadows.com forums and via Slashdot.
Changelog: 2008-06-25: Added CVE reference.
2008-06-26: Added links to "Other References" section.
2008-08-01: Updated "Solution" section. Added vendor link to the "Original Advisory" section.
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.