First published: Thu Aug 06 2009(Updated: )
Apple Mac OS X 10.5 before 10.5.8 does not properly share file descriptors over local sockets, which allows local users to cause a denial of service (system crash) by placing file descriptors in messages sent to a socket that has no receiver, related to a "synchronization issue."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS and macOS | =10.5.2-2008-002 | |
Apple macOS Server | =10.5.2 | |
Apple iOS and macOS | =10.5.6 | |
Apple iOS and macOS | =10.5.5 | |
Apple macOS Server | =10.5.5 | |
Apple iOS and macOS | =10.5.1 | |
Apple macOS Server | =10.5.1 | |
Apple macOS Server | =10.5.6 | |
Apple iOS and macOS | =10.5.3 | |
Apple iOS and macOS | =10.5.0 | |
Apple macOS Server | =10.5.0 | |
Apple macOS Server | =10.5.3 | |
Apple iOS and macOS | =10.5 | |
Apple macOS Server | =10.5.4 | |
Apple iOS and macOS | =10.5.2 | |
Apple macOS Server | =10.5.7 | |
Apple iOS and macOS | =10.5.6 | |
Apple iOS and macOS | =10.5.7 | |
Apple macOS Server | =10.5 | |
Apple iOS and macOS | =10.5.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-2194 is classified as a denial of service vulnerability that can cause a system crash.
To mitigate CVE-2009-2194, it's recommended to update to Mac OS X 10.5.8 or later versions.
CVE-2009-2194 affects Apple Mac OS X versions 10.5 through 10.5.7, including the server versions.
Yes, local users can exploit CVE-2009-2194 by sending malformed file descriptors over local sockets.
CVE-2009-2194 involves a synchronization issue that leads to improper handling of file descriptors over local sockets.