CVE-2006-1471
—CVSS 2.0
4.6 medium
EPSS
—
Published
()
Modified
Description
Format string vulnerability in the CF_syslog function launchd in Apple Mac OS X 10.4 up to 10.4.6 allows local users to execute arbitrary code via format string specifiers that are not properly handled in a syslog call in the logging facility, as demonstrated by using a crafted plist file.
- Vendors
- apple
- Products
- mac os x, mac os x server
- Weakness
- CWE-134
- Vector
- AV:L/AC:L/Au:N/C:P/I:P/A:P
In the news0 stories
No ingested article mentions this CVE yet.