Multiple integer overflows in a "legacy serialization format" parser in AppKit in Apple Mac OS X 10.4.11 allows remote attackers to execute arbitrary code via a crafted serialized property list.
Vector
NETWORK
Complexity
MEDIUM
Authentication
NONE
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL
Advisory | Patch | Confirmed | Link |
---|---|---|---|
ADV-2008-0924 | |||
TA08-079A | |||
1019648 | |||
28358 | |||
28304 | |||
APPLE-SA-2008-03-18 | |||
http://docs.info.apple.com/article.html?artnum=307562 | |||
macos-appkit-parser-bo(41298) |