Overview
There is a vulnerability in the Mac OS X CoreFoundation framework that could allow a local attacker to execute arbitrary code.
Description
| The Core Foundation framework (CoreFoundation.framework) is designed to allow code and data sharing between frameworks, libraries, and applications in different environments and layers. There is a buffer overflow vulnerability in the way CoreFoundation processes a certain environment variable. By specifying a specially crafted value for this variable, an authenticated, local attacker could execute arbitrary code with privileges of the vulnerable process. | 
Impact
| An authenticated, local attacker could execute arbitrary code with privileges of the vulnerable process. | 
Solution
| Apple has released a patch to address this vulnerability. For further details, please see the Apple Security Advisory (Security Update 2004-09-07). | 
Vendor Information
CVSS Metrics
| Group | Score | Vector | 
|---|---|---|
| Base | ||
| Temporal | ||
| Environmental | 
References
Acknowledgements
This vulnerability was reported by Apple.
This document was written by Damon Morda based on information provided by Apple.
Other Information
| CVE IDs: | CVE-2004-0822 | 
| Severity Metric: | 9.62 | 
| Date Public: | 2004-09-08 | 
| Date First Published: | 2004-09-09 | 
| Date Last Updated: | 2004-09-29 19:48 UTC | 
| Document Revision: | 18 |