OSVDB ID: 32693

Title: Apple Mac OS X Minimal SLP v2 Service Agent (slpd) Registration Request Overflow

Info

Disclosure

Jan 17, 2007

Discovery

Jan 18, 2007

Dates

Exploit

Jan 17, 2007

Solution

Feb 11, 2008

Description

A buffer overflow exists in Mac OS X. slpd fails to validate the attr-list field of registration requests resulting in a stack overflow. With a specially crafted request, a local attacker can cause arbitrary code execution resulting in a loss of integrity.

Classification

Location: Local Access Required
Attack Type: Input Manipulation
Impact: Loss of Integrity
Solution: Patch / RCS
Exploit: Exploit Public
Disclosure: Vendor Verified, Uncoordinated Disclosure

Solution

Currently, there are no known workarounds or upgrades to correct this issue. However, Apple has released a patch to address this vulnerability.

Products

Apple Computer, Inc.

Mac OS X

10.4.8
10.4.3
10.4.4
10.4.1
10.4.6
10.4.2
10.4.10
10.4.5
10.4.7
10.4.9
10.4
10.4.11

References

Credit

  • Kevin Finisterre - kfdigitalmunition.com -


Direct URL: http://osvdb.org/32693