Exploit Apple Mac OSX 10.4.x - Software Update Format String

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
29523
Проверка EDB
  1. Пройдено
Автор
KF
Тип уязвимости
DOS
Платформа
OSX
CVE
cve-2007-0463
Дата публикации
2007-01-25
Apple Mac OSX 10.4.x - Software Update Format String
Код:
source: https://www.securityfocus.com/bid/22222/info

Apple Software Update is prone to a format-string vulnerability.

This issue presents itself because the application fails to properly sanitize user-supplied input before passing it as the format specifier to a formatted-printing function.

A successful attack may crash the application or possibly lead to arbitrary code execution. This may facilitate unauthorized access or privilege escalation in the context of the user running the application. 

$ touch %x.%x.%x.%x.%x.%x.%x.swutmp
$ open %x.%x.%x.%x.%x.%x.%x.swutmp
 
Источник
www.exploit-db.com

Похожие темы