Apple OS X DYLD_PRINT_TO_FILE Privilege Escalation
Posted by deepcore on July 24, 2015 – 5:39 am
In Apple OS X 10.10.4 and prior, the DYLD_PRINT_TO_FILE environment variable is used for redirecting logging data to a file instead of stderr. Due to a design error, this feature can be abused by a local attacker to write arbitrary files as root via restricted, SUID-root binaries.
Post a reply
You must be logged in to post a comment.