Exploitation Summary
EIP tracks 2 public exploits for CVE-2007-2386.
PoCs published by Metasploit, ddz, including Metasploit module exploits/osx/mdns/upnp_location.
AI-analyzed exploit summary This Metasploit module exploits a buffer overflow in Mac OS X mDNSResponder (CVE-2007-2386) by sending a crafted UPnP response to trigger remote code execution. It targets vulnerable versions of Mac OS X 10.4.x and uses a UDP-based attack vector.
Description
Buffer overflow in mDNSResponder in Apple Mac OS X 10.4 up to 10.4.9 allows remote attackers to cause a denial of service (application termination) or execute arbitrary code via a crafted UPnP Internet Gateway Device (IGD) packet.
Exploits (2)
This Metasploit module exploits a buffer overflow in Mac OS X mDNSResponder (CVE-2007-2386) by sending a crafted UPnP response to trigger remote code execution. It targets vulnerable versions of Mac OS X 10.4.x and uses a UDP-based attack vector.
This Metasploit module exploits a buffer overflow in Mac OS X mDNSResponder (CVE-2007-2386) by sending a crafted UPnP response to trigger remote code execution. It targets specific offsets and architectures (x86/PPC) to overwrite function pointers and execute payloads.