Dropbox FinderLoadBundle OS X Local...

- AV AC AU C I A
发布: 2015-10-01
修订: 2025-04-13

The setuid root FinderLoadBundle that was included in older DropboxHelperTools versions for OS X allows loading of dynamically linked shared libraries that are residing in the same directory. The directory in which FinderLoadBundle is located is owned by root and that prevents placing arbitrary files there. But creating a hard link from FinderLoadBundle to somewhere in a directory in /tmp circumvents that protection thus making it possible to load a shared library containing a payload which creates a root shell.

0%
当前有1条漏洞利用/PoC
当前有0条受影响产品信息