CVE-2006-1443Integer Underflow (Wrap or Wraparound) in Apple MAC OS X

2 documents2 sources
Severity
6.5MEDIUMNVD
EPSS
0.7%
top 28.09%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 12
Latest updateMay 1

Description

Integer underflow in CoreFoundation in Apple Mac OS X 10.3.9 and 10.4.6 allows context-dependent attackers to execute arbitrary code via unspecified vectors involving conversions from string to file system representation within (1) CFStringGetFileSystemRepresentation or (2) getFileSystemRepresentation:maxLength:withPath in NSFileManager, and possibly other similar API functions.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 8.0 | Impact: 6.4

Affected Packages1 packages

NVDapple/mac_os_x10.3.9, 10.4.6+1

Patches

🔴Vulnerability Details

1
GHSA
GHSA-chqp-jwrw-7jp8: Integer underflow in CoreFoundation in Apple Mac OS X 102022-05-01