Multiple integer overflows in the SearchKit API in Apple Mac OS X 10.4.11 and 10.5 through 10.5.4 allow context-dependent attackers to cause a denial of service (application crash) or execute arbitrary code via vectors associated with "passing untrusted input" to unspecified API functions.
Weaknesses in this category are related to improper calculation or conversion of numbers.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/31189 | vdb entry patch |
http://lists.apple.com/archives/security-announce//2008/Sep/msg00005.html | patch vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/45172 | vdb entry |
http://www.us-cert.gov/cas/techalerts/TA08-260A.html | third party advisory us government resource |
http://securitytracker.com/id?1020880 | vdb entry |
http://www.vupen.com/english/advisories/2008/2584 | vdb entry |
http://secunia.com/advisories/31882 | third party advisory |