CVE-2008-2320

Stack-based buffer overflow in CarbonCore in Apple Mac OS X 10.4.11 and 10.5.4, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via a long filename to the file management API.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:apple:mac_os_x:10.4.11:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.5.4:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x_server:10.4.11:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x_server:10.5.4:*:*:*:*:*:*:*
cpe:2.3:a:apple:carboncore:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2008-08-04 01:41

Updated : 2024-02-04 17:33


NVD link : CVE-2008-2320

Mitre link : CVE-2008-2320

CVE.ORG link : CVE-2008-2320


JSON object : View

Products Affected

apple

  • mac_os_x
  • carboncore
  • mac_os_x_server
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer