vendor:
Mac OS X
by:
Unknown
5.5
CVSS
MEDIUM
Memory Corruption
119
CWE
Product Name: Mac OS X
Affected Version From: Apple Mac OS X 10.5.8 32bits, Apple Mac OS X 10.6.2 64bits
Affected Version To:
Patch Exists: NO
Related CWE: CVE-2010-1840
CPE: o:apple:mac_os_x:10.5.8, cpe:/o:apple:mac_os_x:10.6.2
Platforms Tested:
2010
Apple Directory Services Memory Corruption
chfn, chpass and chsh dos not properly parse authname switch ("-u"), which causes the applications to crash when parsing a long string. Those binaries are setuid root by default.
Mitigation:
Update to a version that has a patch available.