vendor:
Mac OS X
by:
Unknown
7.5
CVSS
HIGH
Integer Overflow
Integer Overflow
CWE
Product Name: Mac OS X
Affected Version From: Mac OS X 10.4.8 and FreeBSD 6.1
Affected Version To: Unknown
Patch Exists: NO
Related CWE: Unknown
CPE: o:apple:mac_os_x:10.4.8
Platforms Tested:
Unknown
Remote Integer-Overflow Vulnerability in Apple Mac OS X
The UFS filesystem handler in Apple Mac OS X fails to handle specially crafted DMG images, leading to a remote integer-overflow vulnerability. A successful exploit can allow a remote attacker to execute arbitrary code with kernel-level privileges, resulting in the complete compromise of affected computers. Failed exploit attempts will cause a denial-of-service condition.
Mitigation:
Unknown