CVE-2008-0988Off-by-one Error in Apple MAC OS X

CWE-1893 documents3 sources
Severity
4.3MEDIUMNVD
EPSS
0.5%
top 35.66%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 18
Latest updateMay 1

Description

Off-by-one error in the Libsystem strnstr API in libc on Apple Mac OS X 10.4.11 allows context-dependent attackers to cause a denial of service (crash) via crafted arguments that trigger a buffer over-read.

CVSS vector

AV:N/AC:M/C:N/I:N/A:PExploitability: 8.6 | Impact: 2.9

Affected Packages2 packages

NVDapple/mac_os_x10.4.11

Patches

🔴Vulnerability Details

2
GHSA
GHSA-p3jw-q26m-j2rr: Off-by-one error in the Libsystem strnstr API in libc on Apple Mac OS X 102022-05-01
CVEList
CVE-2008-0988: Off-by-one error in the Libsystem strnstr API in libc on Apple Mac OS X 102008-03-18
CVE-2008-0988 — Off-by-one Error in Apple MAC OS X | cvebase