CVE-2008-2310
published 2008-07-01CVE-2008-2310: Format string vulnerability in c++filt in Apple Mac OS X 10.5 before 10.5.4 allows user-assisted attackers to execute arbitrary code or cause a denial of…
PriorityP424medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
2.51%
83.1th percentile
Format string vulnerability in c++filt in Apple Mac OS X 10.5 before 10.5.4 allows user-assisted attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted string in (1) C++ or (2) Java source code.
Affected
35 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | <= 10.5.3 | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x_server | <= 10.5.3 | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8LOW
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2008-2310: binutils - Format string vulnerability in c++filt in Apple Mac OS X 10.5 before 10.5.4 allo...
vendor_debian·2008·CVSS 6.8
CVE-2008-2310 [MEDIUM] CVE-2008-2310: binutils - Format string vulnerability in c++filt in Apple Mac OS X 10.5 before 10.5.4 allo...
Format string vulnerability in c++filt in Apple Mac OS X 10.5 before 10.5.4 allows user-assisted attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted string in (1) C++ or (2) Java source code.
Scope: local
bookworm: resolved (fixed in 2.18.1~cvs20080103-1)
bullseye: resolved (fixed in 2.18.1~cvs20080103-1)
forky: resolved (fixed in 2.18.1~cvs20080103-1)
sid: resolved (fixed in 2.18.1~cvs20080103-1)
trixie: resolved (fixed in 2.18.1~cvs20080103-1)
Red Hat
c++filt format string flaw
vendor_redhat·2007-11-26·CVSS 6.8
CVE-2008-2310 [MEDIUM] c++filt format string flaw
c++filt format string flaw
Format string vulnerability in c++filt in Apple Mac OS X 10.5 before 10.5.4 allows user-assisted attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted string in (1) C++ or (2) Java source code.
Statement: Not vulnerable. This issue does not affect the version of c++filt as shipped with binutils in Red Hat Enterprise Linux 3 or 4. Although this bug is present in the version of c++filt as shipped with binutils in Red Hat Enterprise Linux 5, the format string protection from FORTIFY_SOURCE makes this unexploitable.
GHSA
GHSA-mx5r-5fpq-f39j: Format string vulnerability in c++filt in Apple Mac OS X 10
ghsa_unreviewed·2022-05-01
CVE-2008-2310 [MEDIUM] CWE-134 GHSA-mx5r-5fpq-f39j: Format string vulnerability in c++filt in Apple Mac OS X 10
Format string vulnerability in c++filt in Apple Mac OS X 10.5 before 10.5.4 allows user-assisted attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted string in (1) C++ or (2) Java source code.
OSV
CVE-2008-2310: Format string vulnerability in c++filt in Apple Mac OS X 10
osv·2008-07-01·CVSS 6.8
CVE-2008-2310 [MEDIUM] CVE-2008-2310: Format string vulnerability in c++filt in Apple Mac OS X 10
Format string vulnerability in c++filt in Apple Mac OS X 10.5 before 10.5.4 allows user-assisted attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted string in (1) C++ or (2) Java source code.
No detection rules found.
No public exploits indexed.
http://lists.apple.com/archives/security-announce/2008//Jun/msg00002.htmlhttp://secunia.com/advisories/30802http://securitytracker.com/id?1020392http://support.apple.com/kb/HT2163http://www.securityfocus.com/bid/30018http://www.vupen.com/english/advisories/2008/1981/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/43494http://lists.apple.com/archives/security-announce/2008//Jun/msg00002.htmlhttp://secunia.com/advisories/30802http://securitytracker.com/id?1020392http://support.apple.com/kb/HT2163http://www.securityfocus.com/bid/30018http://www.vupen.com/english/advisories/2008/1981/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/43494
2008-07-01
Published