CVE-2015-1134
published 2015-04-10CVE-2015-1134: fontd in Apple Type Services (ATS) in Apple OS X before 10.10.3 allows local users to gain privileges via unspecified vectors, a different vulnerability than…
PriorityP427high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.56%
43.6th percentile
fontd in Apple Type Services (ATS) in Apple OS X before 10.10.3 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2015-1131, CVE-2015-1132, CVE-2015-1133, and CVE-2015-1135.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | < 10.10.3 | 10.10.3 |
| apple | os_x_yosemite_v10.10.3_and_security_update_2015-004 | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8chp-c6p4-xcv5: fontd in Apple Type Services (ATS) in Apple OS X before 10
ghsa_unreviewed·2022-05-14·CVSS 7.2
CVE-2015-1133 [HIGH] CWE-20 GHSA-8chp-c6p4-xcv5: fontd in Apple Type Services (ATS) in Apple OS X before 10
fontd in Apple Type Services (ATS) in Apple OS X before 10.10.3 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2015-1131, CVE-2015-1132, CVE-2015-1134, and CVE-2015-1135.
GHSA
GHSA-vgj7-5chx-3pc8: fontd in Apple Type Services (ATS) in Apple OS X before 10
ghsa_unreviewed·2022-05-14·CVSS 7.2
CVE-2015-1132 [HIGH] CWE-20 GHSA-vgj7-5chx-3pc8: fontd in Apple Type Services (ATS) in Apple OS X before 10
fontd in Apple Type Services (ATS) in Apple OS X before 10.10.3 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2015-1131, CVE-2015-1133, CVE-2015-1134, and CVE-2015-1135.
GHSA
GHSA-qrcw-fxf5-mcw6: fontd in Apple Type Services (ATS) in Apple OS X before 10
ghsa_unreviewed·2022-05-14·CVSS 7.2
CVE-2015-1135 [HIGH] CWE-20 GHSA-qrcw-fxf5-mcw6: fontd in Apple Type Services (ATS) in Apple OS X before 10
fontd in Apple Type Services (ATS) in Apple OS X before 10.10.3 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2015-1131, CVE-2015-1132, CVE-2015-1133, and CVE-2015-1134.
GHSA
GHSA-ghcq-pgwv-hvxp: fontd in Apple Type Services (ATS) in Apple OS X before 10
ghsa_unreviewed·2022-05-14·CVSS 7.2
CVE-2015-1134 [HIGH] CWE-20 GHSA-ghcq-pgwv-hvxp: fontd in Apple Type Services (ATS) in Apple OS X before 10
fontd in Apple Type Services (ATS) in Apple OS X before 10.10.3 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2015-1131, CVE-2015-1132, CVE-2015-1133, and CVE-2015-1135.
GHSA
GHSA-6x5j-jg26-j3c8: fontd in Apple Type Services (ATS) in Apple OS X before 10
ghsa_unreviewed·2022-05-14·CVSS 10.0
CVE-2015-1131 [CRITICAL] CWE-20 GHSA-6x5j-jg26-j3c8: fontd in Apple Type Services (ATS) in Apple OS X before 10
fontd in Apple Type Services (ATS) in Apple OS X before 10.10.3 allows local users to gain privileges via unspecified vectors, a different vulnerability than CVE-2015-1132, CVE-2015-1133, CVE-2015-1134, and CVE-2015-1135.
Kernel
namei: allow restricted O_CREAT of FIFOs and regular files
kernel_security·2018-08-23·CVSS 7.2
CVE-2000-1134 [HIGH] namei: allow restricted O_CREAT of FIFOs and regular files
namei: allow restricted O_CREAT of FIFOs and regular files
Disallows open of FIFOs or regular files not owned by the user in world
writable sticky directories, unless the owner is the same as that of the
directory or the file is opened without the O_CREAT flag. The purpose
is to make data spoofing attacks harder. This protection can be turned
on and off separately for FIFOs and regular files via sysctl, just like
the symlinks/hardlinks protection. This patch is based on Openwall's
"HARDEN_FIFO" feature by Solar Designer.
This is a brief list of old vulnerabilities that could have been prevented
by this feature, some of them even allow for privilege escalation:
CVE-2000-1134
CVE-2007-3852
CVE-2008-0525
CVE-2009-0416
CVE-2011-4834
CVE-2015-1838
CVE-2015-7442
CVE-2016-7489
This list is no
Apple
CVE-2015-1134: OS X Yosemite v10.10.3 and Security Update 2015-004
vendor_apple·CVSS 7.2
CVE-2015-1134 [HIGH] CVE-2015-1134: OS X Yosemite v10.10.3 and Security Update 2015-004
Apple Security Update: About the security content of OS X Yosemite v10.10.3 and Security Update 2015-004
Product: OS X Yosemite v10.10.3 and Security Update 2015-004
CVE: CVE-2015-1134
Component: CVE-ID
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lists.apple.com/archives/security-announce/2015/Apr/msg00001.htmlhttp://www.securityfocus.com/bid/73982http://www.securitytracker.com/id/1032048https://support.apple.com/HT204659http://lists.apple.com/archives/security-announce/2015/Apr/msg00001.htmlhttp://www.securityfocus.com/bid/73982http://www.securitytracker.com/id/1032048https://support.apple.com/HT204659
2015-04-10
Published