Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2008-1576

Overview

Vulnerability Score 6.8 6.8
CVE Id CVE-2008-1576
Last Modified 07 Mar 2011 12:00:00
Published 02 Jun 2008 05:30:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity MEDIUM
Authentication NONE

CVE-2008-1576

Summary

Mail in Apple Mac OS X before 10.5, when an IPv6 SMTP server is used, does not properly initialize memory, which might allow remote attackers to execute arbitrary code or cause a denial of service (application crash), or obtain sensitive information (memory contents) in opportunistic circumstances, by sending an e-mail message.

Vulnerable Systems

Operating System

  • Apple Mac Os X 10.0

  • Apple Mac Os X 10.1

  • Apple Mac Os X 10.2

  • Apple Mac Os X 10.3

  • Apple Mac Os X 10.4


References

CERT - TA08-150A

SECTRACK - 1020140

XF - macosx-mail-code-execution(42723)

VUPEN - ADV-2008-1697

BID - 29500

BID - 29412

SECUNIA - 30430

APPLE - APPLE-SA-2008-05-28

Related Patches

Apple 2008-05-28 Security Update 2008-003 (PPC)

Apple 2008-05-28 Security Update 2008-003 Server (PPC)

Apple 2008-05-28 Security Update 2008-003 (Intel)

Apple 2008-05-28 Security Update 2008-003 Server (Universal)


Last Updated: 27 May 2016 10:47:34