CVE-2005-0970Link Following in Apple MAC OS X

Severity
7.6HIGHNVD
EPSS
0.5%
top 34.74%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 2
Latest updateMay 1

Description

Mac OS X 10.3.9 and earlier allows users to install, create, and execute setuid/setgid scripts, contrary to the intended design, which may allow attackers to conduct unauthorized activities with escalated privileges via vulnerable scripts.

CVSS vector

AV:N/AC:H/C:C/I:C/A:CExploitability: 4.9 | Impact: 10.0

Affected Packages1 packages

NVDapple/mac_os_x30 versions+29

🔴Vulnerability Details

1
GHSA
GHSA-f5r2-gw52-4g6v: Mac OS X 102022-05-01

📋Vendor Advisories

1
Red Hat
ncompress: insecure tmp file handling may lead to file overwrite2021-11-09