First published: Tue Nov 10 2009(Updated: )
Event Monitor in Apple Mac OS X 10.5.8 does not properly handle crafted authentication data sent to an SSH daemon, which allows remote attackers to cause a denial of service via vectors involving processing of XML log documents by other services, related to a "log injection" issue.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple macOS Server | =10.5.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-2829 is classified as a high severity vulnerability due to its potential to cause denial of service.
To fix CVE-2009-2829, update to a later version of Mac OS X beyond 10.5.8, where the vulnerability has been patched.
CVE-2009-2829 affects Apple Mac OS X Server version 10.5.8.
Yes, CVE-2009-2829 can be exploited remotely through crafted authentication data sent to the SSH daemon.
The implications of CVE-2009-2829 include the potential for denial of service attacks affecting services dependent on XML log processing.