7.2
CVSSv2

CVE-2009-1238

Published: 02/04/2009 Updated: 29/09/2017
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Race condition in the HFS vfs sysctl interface in XNU 1228.8.20 and previous versions on Apple Mac OS X 10.5.6 and previous versions allows local users to cause a denial of service (kernel memory corruption) by simultaneously executing the same HFS_SET_PKG_EXTENSIONS code path in multiple threads, which is problematic because of lack of mutex locking for an unspecified global variable.

Vulnerable Product Search on Vulmon Subscribe to Product

apple mac os x 10.0.0

apple mac os x 10.0.1

apple mac os x 10.1.2

apple mac os x 10.1.3

apple mac os x 10.2.4

apple mac os x 10.2.5

apple mac os x 10.3.2

apple mac os x 10.3.3

apple mac os x 10.4

apple mac os x 10.4.0

apple mac os x 10.4.1

apple mac os x 10.4.6

apple mac os x 10.4.7

apple mac os x 10.5.0

apple mac os x 10.5.1

apple mac os x server 10.0.0

apple mac os x server 10.0.1

apple mac os x server 10.1.2

apple mac os x server 10.1.3

apple mac os x server 10.2.3

apple mac os x server 10.2.4

apple mac os x server 10.3.2

apple mac os x server 10.3.3

apple mac os x server 10.4

apple mac os x server 10.4.0

apple mac os x server 10.4.5

apple mac os x server 10.4.6

apple mac os x server 10.5.3

apple mac os x server 10.5.4

apple mac os x 10.0.4

apple mac os x 10.1

apple mac os x 10.2.0

apple mac os x 10.2.1

apple mac os x 10.2.8

apple mac os x 10.3

apple mac os x 10.3.6

apple mac os x 10.3.7

apple mac os x 10.4.2

apple mac os x 10.4.3

apple mac os x 10.4.8

apple mac os x 10.5.3

apple mac os x 10.5.4

apple mac os x server 10.0.4

apple mac os x server 10.1

apple mac os x server 10.2

apple mac os x server 10.2.0

apple mac os x server 10.2.7

apple mac os x server 10.2.8

apple mac os x server 10.3

apple mac os x server 10.3.6

apple mac os x server 10.3.7

apple mac os x server 10.4.11

apple mac os x server 10.4.2

apple mac os x server 10.4.9

apple mac os x server 10.5

apple mac os x server 10.5.0

apple mac os x 10.0.2

apple mac os x 10.0.3

apple mac os x 10.1.4

apple mac os x 10.1.5

apple mac os x 10.2

apple mac os x 10.2.6

apple mac os x 10.2.7

apple mac os x 10.3.4

apple mac os x 10.3.5

apple mac os x 10.4.10

apple mac os x 10.4.11

apple mac os x 10.5.2

apple mac os x server 10.0.2

apple mac os x server 10.0.3

apple mac os x server 10.1.4

apple mac os x server 10.1.5

apple mac os x server 10.2.5

apple mac os x server 10.2.6

apple mac os x server 10.3.4

apple mac os x server 10.3.5

apple mac os x server 10.4.1

apple mac os x server 10.4.10

apple mac os x server 10.4.7

apple mac os x server 10.4.8

apple mac os x server 10.5.5

apple mac os x server

apple mac os x 10.0

apple mac os x 10.1.0

apple mac os x 10.1.1

apple mac os x 10.2.2

apple mac os x 10.2.3

apple mac os x 10.3.0

apple mac os x 10.3.1

apple mac os x 10.3.8

apple mac os x 10.3.9

apple mac os x 10.4.4

apple mac os x 10.4.5

apple mac os x 10.4.9

apple mac os x 10.5

apple mac os x 10.5.5

apple mac os x

apple mac os x server 10.0

apple mac os x server 10.1.0

apple mac os x server 10.1.1

apple mac os x server 10.2.1

apple mac os x server 10.2.2

apple mac os x server 10.3.0

apple mac os x server 10.3.1

apple mac os x server 10.3.8

apple mac os x server 10.3.9

apple mac os x server 10.4.3

apple mac os x server 10.4.4

apple mac os x server 10.5.1

apple mac os x server 10.5.2

Exploits

/* xnu-vfssysctl-dosc * * Copyright (c) 2008 by <mu-b@digit-labsorg> * * Apple MACOS X xnu <= 1228x local kernel DoS POC * by mu-b - Wed 19 Nov 2008 * * - Tested on: Apple MACOS X 1055 (xnu-1228820~1/RELEASE_I386) * * - Private Source Code -DO NOT DISTRIBUTE - * wwwdigit-labsorg/ -- Digit-Labs 2008!@$! */ #in ...