CVE-2006-5710
Apple Airport - 802.11 Probe Response Kernel Memory Corruption (PoC)
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
4Exploited in Wild
-Decision
Descriptions
The Airport driver for certain Orinoco based Airport cards in Darwin kernel 8.8.0 in Apple Mac OS X 10.4.8, and possibly other versions, allows remote attackers to execute arbitrary code via an 802.11 probe response frame without any valid information element (IE) fields after the header, which triggers a heap-based buffer overflow.
El controlador Aeropuerto para cierto Orinoco basados en tarjetas de aeropuerto en Darwin kernel 8.8.0 en Apple Mac OS X 10.4.8, y posiblemente otras versiones, permite a un atacante remoto ejecutar código de su elección a través de una vetana de respuesta de prueba 802.11 sin ningún campo elemento de validación de información (IE) después de la cabecera, lo cual dispara un desbordamiento de búfer basado en pila.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2006-11-01 First Exploit
- 2006-11-03 CVE Reserved
- 2006-11-04 CVE Published
- 2024-08-07 CVE Updated
- 2024-09-24 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (14)
URL | Tag | Source |
---|---|---|
http://docs.info.apple.com/article.html?artnum=304829 | X_refsource_confirm | |
http://secunia.com/advisories/23155 | Third Party Advisory | |
http://securitytracker.com/id?1017151 | Vdb Entry | |
http://www.kb.cert.org/vuls/id/191336 | Third Party Advisory | |
http://www.osvdb.org/30180 | Vdb Entry | |
http://www.us-cert.gov/cas/techalerts/TA06-333A.html | Third Party Advisory | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/29965 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/2700 | 2006-11-01 | |
http://projects.info-pull.com/mokb/MOKB-01-11-2006.html | 2024-08-07 | |
http://secunia.com/advisories/22679 | 2024-08-07 | |
http://www.securityfocus.com/bid/20862 | 2024-08-07 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://lists.apple.com/archives/security-announce/2006/Nov/msg00001.html | 2017-07-20 | |
http://www.vupen.com/english/advisories/2006/4313 | 2017-07-20 | |
http://www.vupen.com/english/advisories/2006/4750 | 2017-07-20 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Apple Search vendor "Apple" | Mac Os X Search vendor "Apple" for product "Mac Os X" | 10.4.8 Search vendor "Apple" for product "Mac Os X" and version "10.4.8" | - |
Affected
| ||||||
Opendarwin Search vendor "Opendarwin" | Darwin Kernel Search vendor "Opendarwin" for product "Darwin Kernel" | 8.8.0 Search vendor "Opendarwin" for product "Darwin Kernel" and version "8.8.0" | - |
Affected
|