notifyd in Apple Mac OS X 10.4.11 does not verify that Mach port death notifications have originated from the kernel, which allows local users to cause a denial of service via spoofed death notifications that prevent other applications from receiving notifications.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/28345 | vdb entry |
http://www.securityfocus.com/bid/28304 | vdb entry |
http://www.us-cert.gov/cas/techalerts/TA08-079A.html | third party advisory us government resource |
http://www.vupen.com/english/advisories/2008/0924/references | vdb entry |
http://secunia.com/advisories/29420 | third party advisory |
http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html | patch vendor advisory |
http://docs.info.apple.com/article.html?artnum=307562 | |
http://www.securitytracker.com/id?1019663 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/41289 | vdb entry |