>> Apple Mac OS X Mach-O Universal Binary Local Privilege Escalation Vulnerabilities
Title : Apple Mac OS X Mach-O Universal Binary Local Privilege Escalation Vulnerabilities VUPEN ID : VUPEN/ADV-2006-4714 CVE ID : CVE-2006-6126 - CVE-2006-6129
Rated as : Moderate Risk
Remotely Exploitable : No Locally Exploitable : Yes Release Date : 2006-11-27
Technical Description
Two vulnerabilities have been identified in Apple Mac OS X, which could be exploited by local attackers to execute arbitrary code or cause a denial of service.
The first flaw is due to an integer overflow error in the "fatfile_getarch2()" function when processing a malformed Mach-O Universal binary, which could be exploited by malicious users to obtain elevated privileges via a specially crafted Mach-O Universal file.
The second issue is due to a memory corruption error when handling Mach-O binaries with malformed "load_command" structures, which could be exploited by local attackers to cause a denial of service or potentially gain elevated privileges.