vendor:
MacOS X SecurityServer
by:
Unknown
7.5
CVSS
HIGH
Denial of Service
20
CWE
Product Name: MacOS X SecurityServer
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE: CVE-2003-0609
CPE: o:apple:mac_os_x
Platforms Tested: MacOS X
Unknown
Apple MacOS X SecurityServer Denial of Service Vulnerability
The vulnerability allows a local user to cause a denial of service (DoS) condition on the target system. This can be achieved by specifying a large password for a SecKeychainUnlock() call. The SecurityServer crashes during a memory copy operation, potentially leading to memory corruption. Although unconfirmed, this could potentially allow for the execution of arbitrary code.
Mitigation:
No known mitigation or remediation for this vulnerability.