PT-2009-3779 · Apple · Xnu+1

Mu-B

·

Published

2009-04-02

·

Updated

2017-09-29

·

CVE-2009-1236

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions XNU versions 1228.3.13 and earlier Mac OS X versions 10.5.6 and earlier
Description A heap-based buffer overflow issue exists in the AppleTalk networking stack, allowing remote attackers to cause a denial of service, resulting in a system crash. This is achieved by sending a ZIP NOTIFY packet that overwrites a certain ifPort structure member.
Recommendations For XNU versions 1228.3.13 and earlier, consider disabling the AppleTalk networking stack as a temporary workaround until a patch is available. For Mac OS X versions 10.5.6 and earlier, restrict access to the AppleTalk networking stack to minimize the risk of exploitation.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-1236

Affected Products

Macos X
Xnu