Vulnerability Description
Format string vulnerability in gm4 (aka m4) on Mac OS X may allow local users to gain privileges if gm4 is called by setuid programs.
CVSS Score
7.2
HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apple | Mac Os X | 10.4.9 |
References
- http://lists.apple.com/mhonarc/security-announce/msg00038.html
- http://marc.info/?l=bugtraq&m=100368233714229&w=2
- http://www.iss.net/security_center/static/10174.php
- http://www.kb.cert.org/vuls/id/147587Third Party AdvisoryUS Government Resource
- http://lists.apple.com/mhonarc/security-announce/msg00038.html
- http://marc.info/?l=bugtraq&m=100368233714229&w=2
- http://www.iss.net/security_center/static/10174.php
- http://www.kb.cert.org/vuls/id/147587Third Party AdvisoryUS Government Resource
FAQ
What is CVE-2001-1411?
CVE-2001-1411 is a vulnerability with a CVSS score of 7.2 (HIGH). Format string vulnerability in gm4 (aka m4) on Mac OS X may allow local users to gain privileges if gm4 is called by setuid programs.
How severe is CVE-2001-1411?
CVE-2001-1411 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2001-1411?
Check the references section above for vendor advisories and patch information. Affected products include: Apple Mac Os X.