First published: Thu Dec 01 2005(Updated: )
System log server in Mac OS X and OS X Server 10.4 through 10.4.3 allows remote attackers to spoof syslog messages in log files by injecting various control characters such as newline (NL).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
macOS Yosemite | =10.4.3 | |
Apple Mac OS X Server | =10.4.3 | |
macOS Yosemite | =10.4.1 | |
Apple Mac OS X Server | =10.4.2 | |
Apple Mac OS X Server | =10.4.1 | |
Apple Mac OS X Server | =10.4 | |
macOS Yosemite | =10.4 | |
macOS Yosemite | =10.4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-3704 is classified as a moderate severity vulnerability due to its potential for log spoofing.
To fix CVE-2005-3704, users should upgrade to a newer version of Mac OS X or OS X Server that addresses this vulnerability.
CVE-2005-3704 affects Mac OS X and OS X Server versions 10.4 through 10.4.3.
CVE-2005-3704 allows remote attackers to inject control characters into log files, potentially altering log data.
CVE-2005-3704 can be exploited by remote attackers with network access to the system.