4.9
CVSSv2

CVE-2010-0105

Published: 27/04/2010 Updated: 10/12/2010
CVSS v2 Base Score: 4.9 | Impact Score: 6.9 | Exploitability Score: 3.9
VMScore: 495
Vector: AV:L/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

The hfs implementation in Apple Mac OS X 10.5.8 and 10.6.x prior to 10.6.5 supports hard links to directories and does not prevent certain deeply nested directory structures, which allows local users to cause a denial of service (filesystem corruption) via a crafted application that calls the mkdir and link functions, related to the fsck_hfs program in the diskdev_cmds component.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apple mac os x 10.5.8

apple mac os x 10.6.0

apple mac os x 10.6.4

apple mac os x 10.6.1

apple mac os x 10.6.3

apple mac os x 10.6.2

Exploits

// -----BEGIN PGP SIGNED MESSAGE----- // Hash: SHA1 /* Proof of Concept for CVE-2010-0105 MacOS X 106 hfs file system attack (Denial of Service) by Maksymilian Arciemowicz from SecurityReasoncom securityreasoncom/achievement_exploitalert/15 NOTE: This DoS will be localized in phase Checking multi-linked directories So we n ...
Mac OS X version 1063 suffers from a HFS related denial of service vulnerability ...
Mac OS X version 1011 suffered from an FTS deep structure of the file system buffer overflow vulnerability ...
MacOS X 1011 suffers from a hardlink bomb issue that causes resource exhaustion ...
The MacOS X 1011 FTS library suffers from a buffer overflow vulnerability ...
Multiple vulnerabilities have been reported in HFS, including a hard linking issue that can be used to trigger a denial of service condition ...