CVE-2006-3508: Buffer Overflow
Published Sep 21, 2006
·Updated
Heap-based buffer overflow in the AirPort wireless driver on Apple Mac OS X 10.4.7 allows physically proximate attackers to cause a denial of service (crash), gain privileges, and execute arbitrary code via a crafted frame that is not properly handled during scan cache updates.
Affected Software
2 affected components
Apple iOS and macOS=10.4.7
Apple Mac OS X Server=10.4.7
Event History
Sep 21, 2006
CVE Published
09:07 PM
Sep 22, 2006
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-3508?
CVE-2006-3508 is classified as a critical vulnerability due to its potential to allow arbitrary code execution and denial of service.
2
How do I fix CVE-2006-3508?
To address CVE-2006-3508, Apple recommends updating to a version of Mac OS X later than 10.4.7.
3
What systems are affected by CVE-2006-3508?
CVE-2006-3508 affects Mac OS X 10.4.7 and Mac OS X Server 10.4.7.
4
What type of vulnerability is CVE-2006-3508?
CVE-2006-3508 is a heap-based buffer overflow vulnerability in the AirPort wireless driver.
5
Can CVE-2006-3508 lead to privilege escalation?
Yes, CVE-2006-3508 can allow attackers to gain elevated privileges on affected systems.