Description
Buffer overflow in CoreAudio in Apple Mac OS X 10.5.8 and 10.6.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MP4 audio file.
CVSS breakdown
CVSS 3.1
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected products
- Apple / mac_os_x10.5.8 – 10.5.8
- Apple / mac_os_x10.6.2 – 10.6.2
- Apple / mac_os_x_server10.5.8 – 10.5.8
- Apple / mac_os_x_server10.6.2 – 10.6.2
References
- MISChttps://exchange.xforce.ibmcloud.com/vulnerabilities/55746
- VENDOR_ADVISORYhttp://support.apple.com/kb/HT4004
- MAILING_LISThttp://lists.apple.com/archives/security-announce/2010/Jan/msg00000.html
- MISChttp://www.securitytracker.com/id?1023472
- MAILING_LISThttp://lists.apple.com/archives/security-announce/2010/Feb/msg00000.html
- MISChttp://www.securityfocus.com/bid/37868
- VENDOR_ADVISORYhttp://support.apple.com/kb/HT4013
- VENDOR_ADVISORYhttp://secunia.com/advisories/38241
- VENDOR_ADVISORYhttp://www.vupen.com/english/advisories/2010/0173