OSVDB ID: 32684

Title: Apple Mac OS X UFS ffs_mountfs() Local Overflow

Info

Disclosure

Jan 10, 2007

Discovery

Unknown

Dates

Exploit

Jan 10, 2007

Solution

Unknown

Description

A local overflow exists in Mac OS X. The ffs_mountfs() fails to validate DMG image files resulting in an integer overflow. With a specially crafted file, an attacker can cause arbitrary code execution resulting in a loss of integrity.

Classification

Location: Local Access Required
Attack Type: Input Manipulation
Impact: Loss of Integrity
Exploit: Exploit Public
Disclosure: OSVDB Verified

Solution

Upgrade to version 10.4.9 or higher, as it has been reported to fix this vulnerability. In addition, Apple has released a patch for some older versions.

Products

Apple Computer, Inc.

Mac OS X

10.4.8
10.3.9

References

Credit

  • LMH - lmhinfo-pull.com -


Direct URL: http://osvdb.org/32684