PT-2007-1790 · Apple · Macos X
Published
2007-01-18
·
Updated
2011-03-08
·
CVE-2007-0318
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions:
Mac OS X version 10.4.8
Description:
The issue allows context-dependent attackers to cause a denial of service, resulting in a kernel panic. This occurs when a crafted HFS+ filesystem in a DMG image is processed, leading to an access of an invalid vnode structure during file removal.
Recommendations:
For Mac OS X version 10.4.8, consider avoiding the use of crafted HFS+ filesystems in DMG images until a fix is available. As a temporary workaround, restrict access to the
do hfs truncate function to minimize the risk of exploitation.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Macos X