Overview
A buffer overflow in Mac OS X Foundation Framework's processing of environment variables may lead to elevated privileges.
Description
A vulnerability is present Mac OS X Foundation Framework shipped in version 10.3.9 of Mac OS X and Mac OSX Server. There is a flaw in the handling of environment variables that may lead to a buffer overflow condition. It is reported that this vulnerability is locally exploitable. |
Impact
Explotation of this vulnerability may lead to the execution of arbitrary code with elevated privileges. |
Solution
Apple has released Security Update 2005-005 to address this issue and several other security related issues. |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
Thanks to Apple Product Security for reporting this vulnerability.
This document was written by Jason A Rafail.
Other Information
CVE IDs: | CVE-2005-1336 |
Severity Metric: | 11.95 |
Date Public: | 2005-05-03 |
Date First Published: | 2005-05-16 |
Date Last Updated: | 2005-05-18 20:25 UTC |
Document Revision: | 9 |