PT-2007-1790 · Apple · Macos X

Published

2007-01-18

·

Updated

2011-03-08

·

CVE-2007-0318

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions: Mac OS X version 10.4.8
Description: The issue allows context-dependent attackers to cause a denial of service, resulting in a kernel panic. This occurs when a crafted HFS+ filesystem in a DMG image is processed, leading to an access of an invalid vnode structure during file removal.
Recommendations: For Mac OS X version 10.4.8, consider avoiding the use of crafted HFS+ filesystems in DMG images until a fix is available. As a temporary workaround, restrict access to the do hfs truncate function to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-0318

Affected Products

Macos X