4.6
CVSSv2

CVE-2006-4866

Published: 19/09/2006 Updated: 05/09/2008
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 465
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Buffer overflow in kextload in Apple OS X, as used by TDIXSupport in Roxio Toast Titanium and possibly other products, allows local users to execute arbitrary code via a long extension argument.

Vulnerable Product Search on Vulmon Subscribe to Product

apple mac os x 10.0

apple mac os x 10.1.2

apple mac os x 10.1.4

apple mac os x 10.2.5

apple mac os x 10.2.7

apple mac os x 10.3.3

apple mac os x 10.3.5

apple mac os x 10.4.2

apple mac os x 10.4.4

apple mac os x server 10.1.2

apple mac os x server 10.1.4

apple mac os x server 10.2.3

apple mac os x server 10.2.5

apple mac os x server 10.3.3

apple mac os x server 10.3.5

apple mac os x server 10.4.2

apple mac os x server 10.4.4

apple mac os x 10.1.5

apple mac os x 10.2

apple mac os x 10.2.1

apple mac os x 10.2.2

apple mac os x 10.2.3

apple mac os x 10.3.7

apple mac os x 10.3.8

apple mac os x 10.3.9

apple mac os x 10.4

apple mac os x server 10.1.5

apple mac os x server 10.2

apple mac os x server 10.2.1

apple mac os x server 10.2.2

apple mac os x server 10.3.7

apple mac os x server 10.3.8

apple mac os x server 10.3.9

apple mac os x server 10.4

apple mac os x 10.0.2

apple mac os x 10.0.3

apple mac os x 10.0.4

apple mac os x 10.1

apple mac os x 10.2.8

apple mac os x 10.3

apple mac os x 10.3.1

apple mac os x 10.3.2

apple mac os x 10.4.6

apple mac os x 10.4.7

apple mac os x server 10.0

apple mac os x server 10.1

apple mac os x server 10.2.7

apple mac os x server 10.2.8

apple mac os x server 10.3

apple mac os x server 10.3.1

apple mac os x server 10.4.5

apple mac os x server 10.4.6

apple mac os x server 10.4.7

apple mac os x 10.0.1

apple mac os x 10.1.1

apple mac os x 10.1.3

apple mac os x 10.2.4

apple mac os x 10.2.6

apple mac os x 10.3.4

apple mac os x 10.3.6

apple mac os x 10.4.1

apple mac os x 10.4.3

apple mac os x 10.4.5

apple mac os x server 10.1.1

apple mac os x server 10.1.3

apple mac os x server 10.2.4

apple mac os x server 10.2.6

apple mac os x server 10.3.2

apple mac os x server 10.3.4

apple mac os x server 10.3.6

apple mac os x server 10.4.1

apple mac os x server 10.4.3

Exploits

source: wwwsecurityfocuscom/bid/20034/info Apple Mac OS X kextload is prone to a buffer-overflow vulnerability because it fails to sufficiently bounds-check user-supplied data before copying it to a finite-sized memory buffer This issue is not exploitable by itself, because kextload is not installed as a setuid-superuser application by ...