← Back

CVE-2003-0171

nvd nist
Published: May 5, 2003Modified: Apr 16, 2026

JSON object

Loading...
7.2
Vector
AV:L/AC:L/Au:N/C:C/I:C/A:C
Exploitability: 3.9 / Impact: 10.0
Source: NVD

Description

DirectoryServices in MacOS X trusts the PATH environment variable to locate and execute the touch command, which allows local users to execute arbitrary commands by modifying the PATH to point to a directory containing a malicious touch program.

Affected (22)

2 products
Mac Os X
Mac Os X Server
Configuration A
22 vulnerable
Vulnerable SoftwareAffected Versions
Apple
Version 10.0.1
Version 10.0.2
Version 10.0.3
Version 10.0.4
Version 10.0
Version 10.1.1
Version 10.1.2
Version 10.1.3
Version 10.1.4
Version 10.1.5
Version 10.1
Version 10.2.1
Version 10.2.2
Version 10.2.3
Version 10.2.4
Version 10.2
Apple
Version 10.0
Version 10.2.1
Version 10.2.2
Version 10.2.3
Version 10.2.4
Version 10.2

References (4)

Timeline

No history available yet.