Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2008-0049
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2008-0049

Description:
AppKit in Apple Mac OS X 10.4.11 inadvertently makes an NSApplication mach port available for inter-process communication instead of inter-thread communication, which allows local users to execute arbitrary code via crafted messages to privileged applications.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/41314

ST
  1019647

SAID
  Secunia Advisory: SA29420

CONFIRM
  http://docs.info.apple.com/article.html?artnum=307562

CERT
  http://www.us-cert.gov/cas/techalerts/TA08-079A.html

BID
  28304
  28340

APPLE
  http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html


Return to the previous page.