Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2005-2759

Quick assessment

Affected
n/a n/a
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

分离 Macintosh上Symantec Norton AntiVirus 9.0.3的LiveUpdate中的jlucaller程序在执行Java程序时运行setuid,可以使本地用户获得特权。

AI Predicted 7.8 Difficulty: Easy EPSS 0.42% · P36
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2005-2759

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
** SPLIT ** The jlucaller program in LiveUpdate for Symantec Norton AntiVirus 9.0.3 on Macintosh runs setuid when executing Java programs, which allows local users to gain privileges. NOTE: due to a CNA error, this candidate was also originally assigned to an issue in DiskMountNotify. Use CVE-2005-3270 for the DiskMountNotify issue, and CVE-2005-2759 for the LiveUpdate issue.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Symantec Norton Antivirus For Macintosh DiskMountNotify 本地特权提升漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
**分离** Macintosh上Symantec Norton AntiVirus 9.0.3的LiveUpdate中的jlucaller程序在执行Java程序时运行setuid,可以使本地用户获得特权。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2005-2759

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2005-2759

登录查看更多情报信息。

Vendor Advisories for CVE-2005-2759 (3)

Other References for CVE-2005-2759 (1)

Same Patch Batch · n/a · 2005-10-20 · 22 CVEs total

CVE-2005-3263 RaRLAB WinRaR 'UNACEV2.DLL'栈溢出漏洞
CVE-2005-3276 Linux Kernel sys_get_thread_area内核信息泄露漏洞
CVE-2005-3275 Linux Kernel NAT 处理内存破坏拒绝服务漏洞
CVE-2005-3274 Linux Kernel IP_VS_CONN_FLUSH 本地拒绝服务漏洞
CVE-2005-3273 Linux Kernel Radionet Open Source Environment 'ndigis'参数验证漏洞
CVE-2005-3272 Linux Kernel Network Bridge不正确转发分组信息泄露漏洞
CVE-2005-3271 Linux Kernel Multithreaded ITimer泄漏本地拒绝服务漏洞
CVE-2005-3270 Symantec LiveUpdate for Macintosh本地特权提升漏洞
CVE-2005-3269 多款目录服务器/证书服务器控制台栈溢出漏洞
CVE-2005-3268 Yiff-Server文件许可绕过漏洞
CVE-2005-3264 Zeroblog Thread.PHP 跨站脚本攻击漏洞
CVE-2005-2469 Novell NetMail NMAP代理远程溢出漏洞
CVE-2005-3262 RARLAB WinRAR UUE/XXE编码文件 远程代码执行漏洞
CVE-2005-3261 VersatileBulletinBoard信息泄露漏洞
CVE-2005-3260 VersatileBulletinBoard多个跨站脚本攻击漏洞
CVE-2005-3259 VersatileBulletinBoard多个SQL注入漏洞
CVE-2005-3258 Squid FTP服务器响应拒绝服务漏洞
CVE-2005-3184 Ethereal服务位置协议处理栈溢出漏洞
CVE-2005-3182 GFI MailSecurity for Exchange/SMTP Web界面远程溢出漏洞
CVE-2005-3121 Debian Module-Assistant以不安全方式创建临时文件漏洞

Showing top 20 of 22 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2005-2759

No comments yet


Leave a comment