Apple Xsan Filesystem Path Name Buffer Overflow Vulnerability
BID:19579
CVE-2006-3506 |Info
Apple Xsan Filesystem Path Name Buffer Overflow Vulnerability
| Bugtraq ID: | 19579 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2006-3506 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 17 2006 12:00AM |
| Updated: | Mar 08 2007 03:35AM |
| Credit: | Andrew Wellington is credited with discovering this vulnerability. |
| Vulnerable: |
Apple Xsan 1.3 Apple Xsan 1.2 Apple Xsan 1.0 |
| Not Vulnerable: |
Apple Xsan 1.4 |
Discussion
Apple Xsan Filesystem Path Name Buffer Overflow Vulnerability
Apple Xsan filesystem is prone to a buffer-overflow vulnerability because the application fails to properly bounds-check user-supplied input before copying it into an insufficiently sized buffer.
This issue may allow remote attackers to execute arbitrary machine code with system privileges on computers directly attached to the vulnerable filesystem. Failed exploit attempts will likely crash the system, denying service to legitimate users.
Apple Xsan filesystem is prone to a buffer-overflow vulnerability because the application fails to properly bounds-check user-supplied input before copying it into an insufficiently sized buffer.
This issue may allow remote attackers to execute arbitrary machine code with system privileges on computers directly attached to the vulnerable filesystem. Failed exploit attempts will likely crash the system, denying service to legitimate users.
Exploit / POC
Apple Xsan Filesystem Path Name Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Apple Xsan Filesystem Path Name Buffer Overflow Vulnerability
Solution:
The vendor released version 1.4 to address this issue. Please see the references for more information.
Solution:
The vendor released version 1.4 to address this issue. Please see the references for more information.
References
Apple Xsan Filesystem Path Name Buffer Overflow Vulnerability
References:
References:
- Apple Security Advisory (Apple)
- Apple Xsan Homepage (Apple)