Vulnerabilities > CVE-2006-5836 - Local Denial of Service vulnerability in Opendarwin Darwin Kernel 8.8.1
Attack vector
LOCAL Attack complexity
LOW Privileges required
NONE Confidentiality impact
COMPLETE Integrity impact
COMPLETE Availability impact
COMPLETE Summary
The fpathconf syscall function in bsd/kern/kern_descrip.c in the Darwin kernel (XNU) 8.8.1 in Apple Mac OS X allows local users to cause a denial of service (kernel panic) and possibly execute arbitrary code via a file descriptor with an unrecognized file type.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
OS | 1 |
Exploit-Db
description | Apple Mac OS X 10.x FPathConf System Call Local Denial of Service Vulnerability. CVE-2006-5836. Dos exploit for osx platform |
id | EDB-ID:28948 |
last seen | 2016-02-03 |
modified | 2006-11-09 |
published | 2006-11-09 |
reporter | ilja van sprundel |
source | https://www.exploit-db.com/download/28948/ |
title | Apple Mac OS X 10.x FPathConf System Call Local Denial of Service Vulnerability |
Nessus
NASL family | MacOS X Local Security Checks |
NASL id | MACOSX_10_4_9.NASL |
description | The remote host is running a version of Mac OS X 10.4 which is older than version 10.4.9 or a version of Mac OS X 10.3 which does not have Security Update 2007-003 applied. This update contains several security fixes for the following programs : - ColorSync - CoreGraphics - Crash Reporter - CUPS - Disk Images - DS Plugins - Flash Player - GNU Tar - HFS - HID Family - ImageIO - Kernel - MySQL server - Networking - OpenSSH - Printing - QuickDraw Manager - servermgrd - SMB File Server - Software Update - sudo - WebLog |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 24811 |
published | 2007-03-13 |
reporter | This script is Copyright (C) 2007-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/24811 |
title | Mac OS X < 10.4.9 Multiple Vulnerabilities (Security Update 2007-003) |
code |
|
References
- http://docs.info.apple.com/article.html?artnum=305214
- http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html
- http://projects.info-pull.com/mokb/MOKB-09-11-2006.html
- http://secunia.com/advisories/22808
- http://secunia.com/advisories/24479
- http://www.osvdb.org/30216
- http://www.securityfocus.com/bid/20982
- http://www.securitytracker.com/id?1017751
- http://www.us-cert.gov/cas/techalerts/TA07-072A.html
- http://www.vupen.com/english/advisories/2006/4448
- http://www.vupen.com/english/advisories/2007/0930
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30152