CVE-2007-0229
CVE-2007-0229
Integer overflow in the ffs_mountfs function in Mac OS X 10.4.8 and FreeBSD 6.1 allows local users to cause a denial of service (panic) and possibly gain privileges via a crafted DMG image that causes "allocation of a negative size buffer" leading to a heap-based buffer overflow, a related issue to CVE-2006-5679. NOTE: a third party states that this issue does not cross privilege boundaries in FreeBSD because only root may mount a filesystem.
Affected products
n/a · n/apublic PoCs found — 1
exploitdbwww.exploit-db.com/exploits/29441unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
http://applefun.blogspot.com/2007/01/moab-10-01-2007-apple-dmg-ufs.htmlhttp://docs.info.apple.com/article.html?artnum=305214http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.htmlhttp://lists.freebsd.org/pipermail/freebsd-security/2007-January/004218.htmlhttp://projects.info-pull.com/moab/MOAB-10-01-2007.htmlhttp://secunia.com/advisories/23703http://secunia.com/advisories/24479https://exchange.xforce.ibmcloud.com/vulnerabilities/31409http://www.osvdb.org/32684http://www.securityfocus.com/bid/21993http://www.securitytracker.com/id?1017751http://www.us-cert.gov/cas/techalerts/TA07-072A.html