CVE
- Id
- 27625
- CVE No.
- CVE-2007-4268
- Status
- Candidate
- Description
- Integer signedness error in the Networking component in Apple Mac OS X 10.4 through 10.4.10 allows local users to execute arbitrary code via a crafted AppleTalk message with a negative value, which satisfies a signed comparison during mbuf allocation but is later interpreted as an unsigned value, which triggers a heap-based buffer overflow.
- Phase
- Assigned (20070809)
- Votes
- None (candidate not yet proposed)
- Comments