CVE-2009-1717: Buffer Overflow
Integer overflow in Terminal in Apple Mac OS X 10.5 before 10.5.7 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted size value in a CSI[4 xterm resize escape sequence that triggers a heap-based buffer overflow.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-1717?
CVE-2009-1717 has a medium severity rating due to its potential for remote code execution or denial of service.
How do I fix CVE-2009-1717?
To fix CVE-2009-1717, upgrade your Mac OS X to version 10.5.7 or later.
What versions of macOS are affected by CVE-2009-1717?
CVE-2009-1717 affects macOS versions 10.5.0 through 10.5.6.
Can CVE-2009-1717 lead to data loss?
Yes, CVE-2009-1717 can cause memory corruption which may result in application crashes and potential data loss.
Is CVE-2009-1717 exploitable over a network?
Yes, CVE-2009-1717 can be exploited remotely through a specially crafted CSI xterm resize escape sequence.