vendor:
Mac OS X
by:
Dan Rosenberg
7.5
CVSS
HIGH
Local Information Disclosure
119
CWE
Product Name: Mac OS X
Affected Version From: Prior to OS X 10.6.7
Affected Version To:
Patch Exists: YES
Related CWE: CVE-2011-0997
CPE: o:apple:mac_os_x
Metasploit:
https://www.rapid7.com/db/vulnerabilities/vmsa-2011-0010-cve-2011-0997/, https://www.rapid7.com/db/vulnerabilities/f5-big-ip-cve-2011-0997/, https://www.rapid7.com/db/vulnerabilities/freebsd-vid-7e69f00d-632a-11e0-9f3a-001d092480a4/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2011-0997/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2011-0997/, https://www.rapid7.com/db/vulnerabilities/centos_linux-cve-2011-0997/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2011-0428/
Platforms Tested:
2011
Apple Mac OS X Local Information Disclosure Vulnerability
Apple Mac OS X is prone to a local information-disclosure vulnerability because of an integer-overflow error in the HFS subsystem. A local attacker can exploit this issue to obtain sensitive information that may lead to further attacks. Due to the nature of this issue, local attackers may be able to execute arbitrary code in the context of the kernel, but this has not been confirmed.
Mitigation:
Upgrade to OS X 10.6.7 or later.