First published: Tue Mar 18 2008(Updated: )
AppKit in Apple Mac OS X 10.4.11 inadvertently makes an NSApplication mach port available for inter-process communication instead of inter-thread communication, which allows local users to execute arbitrary code via crafted messages to privileged applications.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Mac OS X Server | =10.4.11 | |
macOS Yosemite | =10.4.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-0049 is considered a high severity vulnerability due to the potential for arbitrary code execution.
To mitigate CVE-2008-0049, you should update to a later version of macOS that addresses this vulnerability.
CVE-2008-0049 affects users of Apple Mac OS X 10.4.11, including both desktop and server editions.
Exploiting CVE-2008-0049 can allow local users to execute arbitrary code within the context of privileged applications.
Currently, the recommended solution for CVE-2008-0049 is to upgrade the operating system, as there are no documented workarounds.