7.2

CVE-2009-1235

Exploit

XNU 1228.9.59 and earlier on Apple Mac OS X 10.5.6 and earlier does not properly restrict interaction between user space and the HFS IOCTL handler, which allows local users to overwrite kernel memory and gain privileges by attaching an HFS+ disk image and performing certain steps involving HFS_GET_BOOT_INFO fcntl calls.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ApplemacOS X Version <= 10.5.6
ApplemacOS X Version10.0
ApplemacOS X Version10.0.0
ApplemacOS X Version10.0.1
ApplemacOS X Version10.0.2
ApplemacOS X Version10.0.3
ApplemacOS X Version10.0.4
ApplemacOS X Version10.1
ApplemacOS X Version10.1.0
ApplemacOS X Version10.1.1
ApplemacOS X Version10.1.2
ApplemacOS X Version10.1.3
ApplemacOS X Version10.1.4
ApplemacOS X Version10.1.5
ApplemacOS X Version10.2
ApplemacOS X Version10.2.0
ApplemacOS X Version10.2.1
ApplemacOS X Version10.2.2
ApplemacOS X Version10.2.3
ApplemacOS X Version10.2.4
ApplemacOS X Version10.2.5
ApplemacOS X Version10.2.6
ApplemacOS X Version10.2.7
ApplemacOS X Version10.2.8
ApplemacOS X Version10.3
ApplemacOS X Version10.3.0
ApplemacOS X Version10.3.1
ApplemacOS X Version10.3.2
ApplemacOS X Version10.3.3
ApplemacOS X Version10.3.4
ApplemacOS X Version10.3.5
ApplemacOS X Version10.3.6
ApplemacOS X Version10.3.7
ApplemacOS X Version10.3.8
ApplemacOS X Version10.3.9
ApplemacOS X Version10.4
ApplemacOS X Version10.4.0
ApplemacOS X Version10.4.1
ApplemacOS X Version10.4.2
ApplemacOS X Version10.4.3
ApplemacOS X Version10.4.4
ApplemacOS X Version10.4.5
ApplemacOS X Version10.4.6
ApplemacOS X Version10.4.7
ApplemacOS X Version10.4.8
ApplemacOS X Version10.4.8 Editionmac_mini
ApplemacOS X Version10.4.8 Editionmacbook
ApplemacOS X Version10.4.8 Editionmacbook_pro
ApplemacOS X Version10.4.9
ApplemacOS X Version10.4.10
ApplemacOS X Version10.4.11
ApplemacOS X Version10.5
ApplemacOS X Version10.5.0
ApplemacOS X Version10.5.1
ApplemacOS X Version10.5.2
ApplemacOS X Version10.5.2 Update2008-002
ApplemacOS X Version10.5.3
ApplemacOS X Version10.5.4
ApplemacOS X Version10.5.5
ApplemacOS X Server Version <= 10.5.6
ApplemacOS X Server Version10.0
ApplemacOS X Server Version10.0.0
ApplemacOS X Server Version10.0.1
ApplemacOS X Server Version10.0.2
ApplemacOS X Server Version10.0.3
ApplemacOS X Server Version10.0.4
ApplemacOS X Server Version10.1
ApplemacOS X Server Version10.1.0
ApplemacOS X Server Version10.1.1
ApplemacOS X Server Version10.1.2
ApplemacOS X Server Version10.1.3
ApplemacOS X Server Version10.1.4
ApplemacOS X Server Version10.1.5
ApplemacOS X Server Version10.2
ApplemacOS X Server Version10.2.0
ApplemacOS X Server Version10.2.1
ApplemacOS X Server Version10.2.2
ApplemacOS X Server Version10.2.3
ApplemacOS X Server Version10.2.4
ApplemacOS X Server Version10.2.5
ApplemacOS X Server Version10.2.6
ApplemacOS X Server Version10.2.7
ApplemacOS X Server Version10.2.8
ApplemacOS X Server Version10.3
ApplemacOS X Server Version10.3.0
ApplemacOS X Server Version10.3.1
ApplemacOS X Server Version10.3.2
ApplemacOS X Server Version10.3.3
ApplemacOS X Server Version10.3.4
ApplemacOS X Server Version10.3.5
ApplemacOS X Server Version10.3.6
ApplemacOS X Server Version10.3.7
ApplemacOS X Server Version10.3.8
ApplemacOS X Server Version10.3.9
ApplemacOS X Server Version10.4
ApplemacOS X Server Version10.4.0
ApplemacOS X Server Version10.4.1
ApplemacOS X Server Version10.4.2
ApplemacOS X Server Version10.4.3
ApplemacOS X Server Version10.4.4
ApplemacOS X Server Version10.4.5
ApplemacOS X Server Version10.4.6
ApplemacOS X Server Version10.4.7
ApplemacOS X Server Version10.4.8
ApplemacOS X Server Version10.4.9
ApplemacOS X Server Version10.4.10
ApplemacOS X Server Version10.4.11
ApplemacOS X Server Version10.5
ApplemacOS X Server Version10.5.0
ApplemacOS X Server Version10.5.1
ApplemacOS X Server Version10.5.2
ApplemacOS X Server Version10.5.3
ApplemacOS X Server Version10.5.4
ApplemacOS X Server Version10.5.5
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.395
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C