CVE-2008-1030Improper Input Validation in Apple MAC OS X

Severity
10.0CRITICALNVD
EPSS
1.9%
top 16.58%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 2
Latest updateMay 1

Description

Integer overflow in the CFDataReplaceBytes function in the CFData API in CoreFoundation in Apple Mac OS X before 10.5.3 allows context-dependent attackers to execute arbitrary code or cause a denial of service (crash) via an invalid length argument, which triggers a heap-based buffer overflow.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages2 packages

NVDapple/mac_os_x4 versions+3
NVDapple/mac_os_x_server4 versions+3

🔴Vulnerability Details

2
GHSA
GHSA-9grh-g87r-7m2j: Integer overflow in the CFDataReplaceBytes function in the CFData API in CoreFoundation in Apple Mac OS X before 102022-05-01
CVEList
CVE-2008-1030: Integer overflow in the CFDataReplaceBytes function in the CFData API in CoreFoundation in Apple Mac OS X before 102008-06-02

💥Exploits & PoCs

1
Exploit-DB
Opium OPI Server and CyanPrintIP - Format String / Denial of Service2008-02-11
CVE-2008-1030 — Improper Input Validation in Apple | cvebase