Security bypass vulnerability in sudo in Apple OS X via vectors related to connecting to the standard input, output and error file descriptors of another terminal - CVE-2013-2777ID: oval:org.secpod.oval:def:26699 | Date: (C)2015-09-11 (M)2023-12-07 |
Class: VULNERABILITY | Family: macos |
The host is installed with Apple Mac OS X or Server 10.10.x through 10.10.4 and is prone to a security bypass vulnerability. A flaw is present in the application, which fails to handle vectors related to connecting to the standard input, output and error file descriptors of another terminal. Successful exploitation allows local users with sudo permissions to hijack the authorization of another terminal.
Platform: |
Apple Mac OS X 10.10 |
Apple Mac OS X Server 10.10 |