CVE

Id
11331  
CVE No.
CVE-2005-0125  
Status
Candidate  
Description
The "at" commands on Mac OS X 10.3.7 and earlier do not properly drop privileges, which allows local users to (1) delete arbitrary files via atrm, (2) execute arbitrary programs via the -f argument to batch, or (3) read arbitrary files via the -f argument to batch, which generates a job file that is readable by the local user.  
Phase
Assigned (20050120)  
Votes
None (candidate not yet proposed)  
Comments