Vulnerability CVE-2009-1237


Published: 2009-04-02   Modified: 2012-02-13

Description:
Multiple memory leaks in XNU 1228.3.13 and earlier on Apple Mac OS X 10.5.6 and earlier allow local users to cause a denial of service (kernel memory consumption) via a crafted (1) SYS_add_profil or (2) SYS___mac_getfsstat system call.

See advisories in our WLB2 database:
Topic
Author
Date
Med.
Mac OS X xnu <= 1228.3.13 (macfsstat) Local Kernel Memory Leak/DoS
mu-b
05.04.2009

Type:

CWE-399

(Resource Management Errors)

CVSS2 => (AV:L/AC:L/Au:N/C:N/I:N/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
4.9/10
6.9/10
3.9/10
Exploit range
Attack complexity
Authentication
Local
Low
No required
Confidentiality impact
Integrity impact
Availability impact
None
None
Complete
Affected software
Apple -> Mac os x 
Apple -> Mac os x server 

 References:
http://www.securityfocus.com/bid/34202
http://www.milw0rm.com/exploits/8264
http://www.milw0rm.com/exploits/8263
http://www.informationweek.com/news/hardware/mac/showArticle.jhtml?articleID=216401181
http://www.digit-labs.org/files/exploits/xnu-profil-leak.c
http://www.digit-labs.org/files/exploits/xnu-macfsstat-leak.c
http://secunia.com/advisories/34424

Copyright 2024, cxsecurity.com

 

Back to Top