Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2006-1471
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2006-1471

Description:
Format string vulnerability in the CF_syslog function launchd in Apple Mac OS X 10.4 up to 10.4.6 allows local users to execute arbitrary code via format string specifiers that are not properly handled in a syslog call in the logging facility, as demonstrated by using a crafted plist file.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/27479

ST
  1016397

SAID
  Secunia Advisory: SA20877

OSVDB
  26933

BUGTRAQ
  http://www.securityfocus.com/archive/1/archive/1/438699/100/0/threaded

BID
  18724
  18686

APPLE
  http://lists.apple.com/archives/security-announce/2006/Jun/msg00000.html


Return to the previous page.