OSVDB ID: 50984

Title: Apple Mac OS X Libsystem strptime API Crafted Date String Memory Corruption

Info

Disclosure

Dec 15, 2008

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Unknown

Description

A memory corruption flaw exists in Mac OS X. The strptime API fails to validate date strings resulting in memory corruption. With a specially crafted date string, an attacker can cause arbitrary code execution resulting in a loss of integrity.

Classification

Location: Local / Remote, Context Dependent
Attack Type: Input Manipulation
Impact: Loss of Integrity
Solution: Upgrade
Exploit: Exploit Unknown
Disclosure: Vendor Verified

Solution

Upgrade to version 10.5.6 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.

Products

Apple Inc.

Mac OS X

10.5.5
10.4.11

References

Credit

Unknown or Incomplete



Direct URL: http://osvdb.org/50984