Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2005-2713Apple MAC OS X vulnerability

3 documents3 sources
Severity
6.8MEDIUMNVD
EPSS
0.2%
top 59.97%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedDec 31
Latest updateMay 1

Description

passwd in Directory Services in Mac OS X 10.3.x before 10.3.9 and 10.4.x before 10.4.5 allows local users to create arbitrary world-writable files as root by specifying an alternate file in the password database option.

CVSS vector

AV:L/AC:L/C:C/I:C/A:CExploitability: 3.1 | Impact: 10.0

Affected Packages2 packages

NVDapple/mac_os_x16 versions+15
NVDapple/mac_os_x_server16 versions+15

Patches

🔴Vulnerability Details

1
GHSA
GHSA-g2mf-456w-65w4: passwd in Directory Services in Mac OS X 102022-05-01

💥Exploits & PoCs

1
Exploit-DB
Apple Mac OSX - '/usr/bin/passwd' Custom Passwd Privilege Escalation2006-03-01