4.6
CVSSv2

CVE-2006-1471

Published: 27/06/2006 Updated: 18/10/2018
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Format string vulnerability in the CF_syslog function launchd in Apple Mac OS X 10.4 up to 10.4.6 allows local users to execute arbitrary code via format string specifiers that are not properly handled in a syslog call in the logging facility, as demonstrated by using a crafted plist file.

Vulnerable Product Search on Vulmon Subscribe to Product

apple mac os x 10.4.5

apple mac os x 10.4.6

apple mac os x server 10.4.6

apple mac os x 10.4.3

apple mac os x 10.4.4

apple mac os x server 10.4.4

apple mac os x server 10.4.5

apple mac os x 10.4

apple mac os x server 10.4

apple mac os x server 10.4.1

apple mac os x 10.4.1

apple mac os x 10.4.2

apple mac os x server 10.4.2

apple mac os x server 10.4.3

Recent Articles

Kaspersky Security Bulletin 2006: Malware for Unix-type systems
Securelist • Konstantin Sapronov • 27 Feb 2007

In spite of their variety, all contemporary operating systems can be divided into two broad categories: Microsoft operating systems and Unix-type systems. This report provides an overview of malicious programs for Unix-type operating systems. Linux is the most popular Unix-type system, and even though it is the main alternative to Windows, it is still predominantly used for server solutions. Like other Unix-type systems, Linux workstations are used by only a handful of enthusiasts and profession...