OS X 10.10 DYLD_PRINT_TO_FILE Local Privilege Escalation Vulnerability

Originator:isaac.greenspan
Number:rdar://22052368 Date Originated:29-Jul-2015 11:32 AM
Status:"Duplicate of 17973575 (Closed)" Resolved:
Product:OS X Product Version:10.10
Classification:Security Reproducible:Always
 
See:
- primarily: https://www.sektioneins.de/en/blog/15-07-07-dyld_print_to_file_lpe.html
- also: https://twitter.com/dev_stdin/status/623549117843832832, https://github.com/sektioneins/SUIDGuard

Comments


Please note: Reports posted here will not necessarily be seen by Apple. All problems should be submitted at bugreport.apple.com before they are posted here. Please only post information for Radars that you have filed yourself, and please do not include Apple confidential information in your posts. Thank you!