HIGH
Heap-based buffer overflow in the AppleTalk networking stack in XNU 1228.3.13 and earlier on Apple Mac OS X 10.5.6 and earlier allows remote attackers to cause a denial of service (system crash) via a ZIP NOTIFY (aka ZIPOP_NOTIFY) packet that overwrites a certain ifPort structure member
Published Apr 2, 2009
10.0
HIGHCVSS 2.0
EPSS 8.41%
Description
Heap-based buffer overflow in the AppleTalk networking stack in XNU 1228.3.13 and earlier on Apple Mac OS X 10.5.6 and earlier allows remote attackers to cause a denial of service (system crash) via a ZIP NOTIFY (aka ZIPOP_NOTIFY) packet that overwrites a certain ifPort structure member.
Affected products
No data.
OR
- ≤ 10.5.6
- 10.0
- 10.0.0
- 10.0.1
- 10.0.2
- 10.0.3
- 10.0.4
- 10.1
- 10.1.0
- 10.1.1
- 10.1.2
- 10.1.3
- 10.1.4
- 10.1.5
- 10.2
- 10.2.0
- 10.2.1
- 10.2.2
- 10.2.3
- 10.2.4
- 10.2.5
- 10.2.6
- 10.2.7
- 10.2.8
- 10.3
- 10.3.0
- 10.3.1
- 10.3.2
- 10.3.3
- 10.3.4
- 10.3.5
- 10.3.6
- 10.3.7
- 10.3.8
- 10.3.9
- 10.4
- 10.4.0
- 10.4.1
- 10.4.2
- 10.4.3
- 10.4.4
- 10.4.5
- 10.4.6
- 10.4.7
- 10.4.8
- 10.4.8
- 10.4.8
- 10.4.8
- 10.4.9
- 10.4.10
- 10.4.11
- 10.5
- 10.5.0
- 10.5.1
- 10.5.2
- 10.5.2
- 10.5.3
- 10.5.4
- 10.5.5
- ≤ 10.5.6
- 10.0
- 10.0.0
- 10.0.1
- 10.0.2
- 10.0.3
- 10.0.4
- 10.1
- 10.1.0
- 10.1.1
- 10.1.2
- 10.1.3
- 10.1.4
- 10.1.5
- 10.2
- 10.2.0
- 10.2.1
- 10.2.2
- 10.2.3
- 10.2.4
- 10.2.5
- 10.2.6
- 10.2.7
- 10.2.8
- 10.3
- 10.3.0
- 10.3.1
- 10.3.2
- 10.3.3
- 10.3.4
- 10.3.5
- 10.3.6
- 10.3.7
- 10.3.8
- 10.3.9
- 10.4
- 10.4.0
- 10.4.1
- 10.4.2
- 10.4.3
- 10.4.4
- 10.4.5
- 10.4.6
- 10.4.7
- 10.4.8
- 10.4.9
- 10.4.10
- 10.4.11
- 10.5
- 10.5.0
- 10.5.1
- 10.5.2
- 10.5.3
- 10.5.4
- 10.5.5
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- http://secunia.com/advisories/34424 third-party-advisoryx_refsource_SECUNIA
- http://www.digit-labs.org/files/exploits/xnu-appletalk-zip.c x_refsource_MISCExploit
- http://www.informationweek.com/news/hardware/mac/showArticle.jhtml?articleID=216401181 x_refsource_MISC
- http://www.securityfocus.com/bid/34201 vdb-entryx_refsource_BIDExploit
- https://www.exploit-db.com/exploits/8262 exploitx_refsource_EXPLOIT-DB
| Link | Providers | Tags |
|---|---|---|
| http://secunia.com/advisories/34424 | third-party-advisoryx_refsource_SECUNIA | |
| http://www.digit-labs.org/files/exploits/xnu-appletalk-zip.c | x_refsource_MISCExploit | |
| http://www.informationweek.com/news/hardware/mac/showArticle.jhtml?articleID=216401181 | x_refsource_MISC | |
| http://www.securityfocus.com/bid/34201 | vdb-entryx_refsource_BIDExploit | |
| https://www.exploit-db.com/exploits/8262 | exploitx_refsource_EXPLOIT-DB |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Apr 2, 2009
Updated Aug 7, 2024
Reserved Apr 2, 2009
Link CVE-2009-1236
CISA Vulnrichment
Updated n/a