search menu icon-carat-right cmu-wordmark

CERT Coordination Center

Apple Mac OS X Apple Type Services server contains multiple buffer overflows

Vulnerability Note VU#800296

Original Release Date: 2006-11-30 | Last Revised: 2006-12-20

Overview

The Apple Mac OS X Apple Type Services server contains multiple buffer overflow vulnerabilities. These vulnerabilities may allow a local attacker to execute arbitrary code with system privileges.

Description

The Apple Mac OS X Apple Type Services server fails to properly validate service requests. A local attacker may be able to trigger the overflow by sending a specially crafted service request to a vulnerable system.

Apple states that this issue does not affect systems prior to Apple Mac OS X v10.4.

Impact

This vulnerability may allow a local attacker to execute arbitrary code with system privileges.

Solution

Apple has addressed this issue with Apple Security Update 2006-007.

Vendor Information

800296
 

CVSS Metrics

Group Score Vector
Base
Temporal
Environmental

References

Acknowledgements

This vulnerability was reported in Apple Security Update 2006-007.

This document was written by Katie Steiner.

Other Information

CVE IDs: CVE-2006-4398
Severity Metric: 8.80
Date Public: 2006-11-28
Date First Published: 2006-11-30
Date Last Updated: 2006-12-20 15:34 UTC
Document Revision: 13

Sponsored by CISA.