CVE-2010-1840
Apple Mac OS X 10.5.8 and 10.6.x < 10.6.5 - Remote Code Execution via Directory Services Password Validation
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2010-1840. PoCs published by Rodrigo Rubira.
AI-analyzed exploit summary This exploit demonstrates a memory corruption vulnerability in Apple's Directory Services utilities (chfn, chpass, chsh) when parsing a long string via the '-u' switch, leading to a crash. The vulnerability is confirmed in Mac OS X 10.5.8 and 10.6.2.
Description
Stack-based buffer overflow in the password-validation functionality in Directory Services in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors.
Exploits (1)
This exploit demonstrates a memory corruption vulnerability in Apple's Directory Services utilities (chfn, chpass, chsh) when parsing a long string via the '-u' switch, leading to a crash. The vulnerability is confirmed in Mac OS X 10.5.8 and 10.6.2.