CVE-2005-3712: Buffer Overflow
Published Dec 31, 2005
·Updated
Heap-based buffer overflow in rsync in Mac OS X 10.4 through 10.4.5 allows remote authenticated users to execute arbitrary code via long extended attributes.
Affected Software
12 affected components
Apple iOS and macOS=10.4.3
Apple Mac OS X Server=10.4.3
Apple iOS and macOS=10.4.1
Apple Mac OS X Server=10.4.2
Apple Mac OS X Server=10.4.4
Apple Mac OS X Server=10.4.1
Apple iOS and macOS=10.4.4
Apple Mac OS X Server=10.4
Apple Mac OS X Server=10.4.5
Apple iOS and macOS=10.4
Apple iOS and macOS=10.4.5
Apple iOS and macOS=10.4.2
Remediation
Patch Available
Patch Available
Event History
Dec 31, 2005
CVE Published
05:00 AM
Mar 3, 2006
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-3712?
CVE-2005-3712 has a high severity rating due to its potential for remote code execution.
2
How do I fix CVE-2005-3712?
To fix CVE-2005-3712, update your Mac OS X system to versions 10.4.6 or later, which include the necessary patches.
3
What is affected by CVE-2005-3712?
CVE-2005-3712 affects Mac OS X versions 10.4 through 10.4.5, including both client and server editions.
4
Who is at risk from CVE-2005-3712?
Users of Mac OS X 10.4 through 10.4.5 who are connected to untrusted networks or systems are at risk from CVE-2005-3712.
5
What kind of attack does CVE-2005-3712 allow?
CVE-2005-3712 allows remote authenticated users to execute arbitrary code on vulnerable systems.