Format string vulnerability in the CF_syslog function launchd in Apple Mac OS X 10.4 up to 10.4.6 allows local users to execute arbitrary code via format string specifiers that are not properly handled in a syslog call in the logging facility, as demonstrated by using a crafted plist file.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2006-06-27 15:13
Updated : 2018-10-18 09:32
NVD link : CVE-2006-1471
Mitre link : CVE-2006-1471
JSON object : View
CWE
CWE-134
Use of Externally-Controlled Format String
Products Affected
apple
- mac_os_x
- mac_os_x_server