vendor:
Mac OS X
by:
Jelmer Kuperus
9.3
CVSS
HIGH
Remote Code Execution
119
CWE
Product Name: Mac OS X
Affected Version From: Mac OS X 10.5.8
Affected Version To: Mac OS X 10.5.8
Patch Exists: YES
Related CWE: CVE-2009-0950
CPE: o:apple:mac_os_x:10.5.8
Other Scripts:
N/A
Platforms Tested: Mac
2009
AFP Server Remote Code Execution Vulnerability
This exploit is a remote code execution vulnerability in the AFP Server service of Mac OS X 10.5.8. It allows an attacker to execute arbitrary code on the vulnerable system by sending a specially crafted AFP request packet. The vulnerability is caused by a stack-based buffer overflow in the AFP Server service, which can be triggered by sending a specially crafted AFP request packet with an overly long filename. The overflow occurs when the filename is copied into a fixed-length buffer on the stack. This can be exploited to execute arbitrary code on the vulnerable system.
Mitigation:
Apple has released a security update to address this vulnerability. Users should upgrade to the latest version of Mac OS X 10.5.8.