// For flags

CVE-2007-0355

Apple Mac OSX 10.4.8 - SLP Daemon Service Registration Buffer Overflow (PoC)

Severity Score

7.2
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Buffer overflow in the Apple Minimal SLP v2 Service Agent (slpd) in Mac OS X 10.4.11 and earlier, including 10.4.8, allows local users, and possibly remote attackers, to gain privileges and possibly execute arbitrary code via a registration request with an invalid attr-list field.

Un desbordamiento de búfer en Apple Minimal SLP v2 Service Agent (slpd) en Mac OS X versión 10.4.11 y anteriores, incluyendo versión 10.4.8, permite a usuarios locales, y posiblemente a atacantes remotos, alcanzar privilegios y posiblemente ejecutar código arbitrario por medio de una petición de registro con un campo attr-list no válido.

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2007-01-18 CVE Reserved
  • 2007-01-19 CVE Published
  • 2023-10-15 EPSS Updated
  • 2024-08-07 CVE Updated
  • 2024-08-07 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Apple
Search vendor "Apple"
Minimal Slp Service Agent
Search vendor "Apple" for product "Minimal Slp Service Agent"
10.4.11
Search vendor "Apple" for product "Minimal Slp Service Agent" and version "10.4.11"
-
Affected
Apple
Search vendor "Apple"
Mac Os X
Search vendor "Apple" for product "Mac Os X"
10.4.8
Search vendor "Apple" for product "Mac Os X" and version "10.4.8"
-
Affected