CVE-2008-2310: Medium severity apple ios and macos vulnerability
Published Jul 1, 2008
·Updated
Format string vulnerability in c++filt in Apple Mac OS X 10.5 before 10.5.4 allows user-assisted attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted string in (1) C++ or (2) Java source code.
Affected Software
30 affected components
Apple iOS and macOS=10.4.3
Apple Mac OS X Server=10.4.3
Apple Mac OS X Server<=10.5.3
Apple Mac OS X Server=10.5.2
Apple Mac OS X Server=10.4.10
Apple Mac OS X Server=10.4.9
Apple Mac OS X Server=10.4.11
Apple iOS and macOS=10.4.1
Apple Mac OS X Server=10.4.2
Apple Mac OS X Server=10.4.4
Apple iOS and macOS=10.5.1
Apple iOS and macOS=10.4.10
Apple Mac OS X Server=10.4.1
Apple iOS and macOS=10.4.9
Apple Mac OS X Server=10.5.1
Apple iOS and macOS<=10.5.3
Apple iOS and macOS=10.4.7
Apple iOS and macOS=10.4.4
Apple iOS and macOS=10.5
Apple Mac OS X Server=10.4.5
Apple iOS and macOS=10.5.2
Apple Mac OS X Server=10.4.6
Apple Mac OS X Server=10.4.8
Apple iOS and macOS=10.4.6
Apple iOS and macOS=10.4.5
Apple iOS and macOS=10.4.11
Apple iOS and macOS=10.4.8
Apple Mac OS X Server=10.5
Apple Mac OS X Server=10.4.7
Apple iOS and macOS=10.4.2
Remediation
Patch Available
Event History
Jul 1, 2008
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-2310?
CVE-2008-2310 is considered a critical severity vulnerability due to its potential to allow arbitrary code execution.
2
How do I fix CVE-2008-2310?
To fix CVE-2008-2310, users should update their Apple Mac OS X to version 10.5.4 or later.
3
What software is affected by CVE-2008-2310?
CVE-2008-2310 affects Apple Mac OS X versions 10.4.1 through 10.5.3.
4
What type of vulnerability is CVE-2008-2310?
CVE-2008-2310 is a format string vulnerability found in the c++filt program.
5
Can CVE-2008-2310 cause a denial of service?
Yes, an exploit of CVE-2008-2310 can lead to application crashes, resulting in a denial of service.