CVE-2008-2310Use of Externally-Controlled Format String in Apple MAC OS X

Severity
6.8MEDIUMNVD
EPSS
0.9%
top 24.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 1
Latest updateMay 1

Description

Format string vulnerability in c++filt in Apple Mac OS X 10.5 before 10.5.4 allows user-assisted attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted string in (1) C++ or (2) Java source code.

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4

Affected Packages3 packages

NVDapple/mac_os_x10.5.3+14
NVDapple/mac_os_x_server10.5.3+14
Debiangnu/binutils< 2.18.1~cvs20080103-1+3

Patches

🔴Vulnerability Details

3
GHSA
GHSA-mx5r-5fpq-f39j: Format string vulnerability in c++filt in Apple Mac OS X 102022-05-01
CVEList
CVE-2008-2310: Format string vulnerability in c++filt in Apple Mac OS X 102008-07-01
OSV
CVE-2008-2310: Format string vulnerability in c++filt in Apple Mac OS X 102008-07-01

📋Vendor Advisories

2
Debian
CVE-2008-2310: binutils - Format string vulnerability in c++filt in Apple Mac OS X 10.5 before 10.5.4 allo...2008
Red Hat
c++filt format string flaw2007-11-26

💬Community

1
Bugzilla
CVE-2008-2310 c++filt format string flaw2008-07-04
CVE-2008-2310 — Apple MAC OS X vulnerability | cvebase