Vulnerability Description
Stack-based buffer overflow in AppleFileServer for Mac OS X 10.3.3 and earlier allows remote attackers to execute arbitrary code via a LoginExt packet for a Cleartext Password User Authentication Method (UAM) request with a PathName argument that includes an AFPName type string that is longer than the associated length field.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apple | Mac Os X | <= 10.3.3 |
| Apple | Mac Os X Server | <= 10.3.3 |
References
- http://lists.apple.com/mhonarc/security-announce/msg00049.html
- http://secunia.com/advisories/11539
- http://securitytracker.com/id?1010039
- http://www.atstake.com/research/advisories/2004/a050304-1.txtPatchVendor Advisory
- http://www.kb.cert.org/vuls/id/648406US Government Resource
- http://www.securiteam.com/securitynews/5QP0115CUO.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16049
- http://lists.apple.com/mhonarc/security-announce/msg00049.html
- http://secunia.com/advisories/11539
- http://securitytracker.com/id?1010039
- http://www.atstake.com/research/advisories/2004/a050304-1.txtPatchVendor Advisory
- http://www.kb.cert.org/vuls/id/648406US Government Resource
- http://www.securiteam.com/securitynews/5QP0115CUO.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16049
FAQ
What is CVE-2004-0430?
CVE-2004-0430 is a vulnerability with a CVSS score of 5.1 (MEDIUM). Stack-based buffer overflow in AppleFileServer for Mac OS X 10.3.3 and earlier allows remote attackers to execute arbitrary code via a LoginExt packet for a Cleartext Password User Authentication Meth...
How severe is CVE-2004-0430?
CVE-2004-0430 has been rated MEDIUM with a CVSS base score of 5.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2004-0430?
Check the references section above for vendor advisories and patch information. Affected products include: Apple Mac Os X, Apple Mac Os X Server.