CVE-2009-2835: Input Validation
Published Nov 10, 2009
·Updated
The kernel in Apple Mac OS X before 10.6.2 does not properly handle task state segments, which allows local users to gain privileges, cause a denial of service (system crash), or obtain sensitive information via unspecified vectors.
Affected Software
118 affected components
Apple iOS and macOS=10.5.8
Apple iOS and macOS=10.4.3
Apple iOS and macOS=10.2.5
Apple iOS and macOS=10.2.7
Apple iOS and macOS=10.0.2
Apple iOS and macOS=10.2.8
Apple iOS and macOS=10.2.1
Apple iOS and macOS=10.5.6
Apple iOS and macOS=10.3.1
Apple iOS and macOS=10.3.5
Apple iOS and macOS=10.3.0
Apple iOS and macOS=10.4.1
Apple iOS and macOS=10.1
Apple iOS and macOS=10.5.5
Apple iOS and macOS=10.5.1
Apple iOS and macOS=10.0.1
Apple iOS and macOS=10.4.10
Apple iOS and macOS=10.0.3
Apple iOS and macOS=10.4.9
Apple iOS and macOS=10.1.4
Apple iOS and macOS=10.2.4
Apple iOS and macOS=10.4.7
Apple iOS and macOS=10.4.4
Apple iOS and macOS=10.6
Apple iOS and macOS=10.3.2
Apple iOS and macOS=10.5.3
Apple iOS and macOS=10.5.0
Apple iOS and macOS=10.2.2
Apple iOS and macOS=10.0
Apple iOS and macOS=10.3.7
Apple iOS and macOS=10.0.0
Apple iOS and macOS=10.4.0
Apple iOS and macOS=10.1.0
Apple iOS and macOS=10.1.3
Apple iOS and macOS=10.5
Apple iOS and macOS=10.3.6
Apple iOS and macOS=10.5.2
Apple iOS and macOS=10.1.5
Apple iOS and macOS=10.4
Apple iOS and macOS=10.2.0
Apple iOS and macOS=10.4.6
Apple iOS and macOS=10.3.8
Apple iOS and macOS=10.1.1
Apple iOS and macOS=10.5.7
Apple iOS and macOS=10.4.5
Apple iOS and macOS=10.3.9
Apple iOS and macOS=10.3.4
Apple iOS and macOS=10.4.11
Apple iOS and macOS=10.4.8
Apple iOS and macOS=10.3.3
Apple iOS and macOS=10.2.6
Apple iOS and macOS<=10.6.1
Apple iOS and macOS=10.2.3
Apple iOS and macOS=10.2
Apple iOS and macOS=10.4.2
Apple iOS and macOS=10.5.4
Apple iOS and macOS=10.3
Apple iOS and macOS=10.0.4
Apple iOS and macOS=10.1.2
Apple Mac OS X Server=10.4.3
Apple Mac OS X Server=10.3.2
Apple Mac OS X Server=10.1.5
Apple Mac OS X Server=10.1
Apple Mac OS X Server=10.3.0
Apple Mac OS X Server=10.2.2
Apple Mac OS X Server=10.1.1
Apple Mac OS X Server=10.2.4
Apple Mac OS X Server=10.2.0
Apple Mac OS X Server=10.5.2
Apple Mac OS X Server=10.4.10
Apple Mac OS X Server=10.4.9
Apple Mac OS X Server<=10.6.1
Apple Mac OS X Server=10.1.2
Apple Mac OS X Server=10.3.7
Apple Mac OS X Server=10.4.11
Apple Mac OS X Server=10.3.5
Apple Mac OS X Server=10.5.8
Apple Mac OS X Server=10.4.2
Apple Mac OS X Server=10.3.3
Apple Mac OS X Server=10.2.7
Apple Mac OS X Server=10.5.5
Apple Mac OS X Server=10.4.4
Apple Mac OS X Server=10.2.3
Apple Mac OS X Server=10.4.1
Apple Mac OS X Server=10.5.1
Apple Mac OS X Server=10.4.0
Apple Mac OS X Server=10.5.6
Apple Mac OS X Server=10.6
Apple Mac OS X Server=10.3.4
Apple Mac OS X Server=10.5.0
Apple Mac OS X Server=10.0.4
Apple Mac OS X Server=10.5.3
Apple Mac OS X Server=10.2.5
Apple Mac OS X Server=10.4
Apple Mac OS X Server=10.5.4
Apple Mac OS X Server=10.4.5
Apple Mac OS X Server=10.3
Apple Mac OS X Server=10.3.8
Apple Mac OS X Server=10.5.7
Apple Mac OS X Server=10.0.0
Apple Mac OS X Server=10.2.6
Apple Mac OS X Server=10.4.6
Apple Mac OS X Server=10.3.9
Apple Mac OS X Server=10.0.3
Apple Mac OS X Server=10.2
Apple Mac OS X Server=10.4.8
Apple Mac OS X Server=10.1.0
Apple Mac OS X Server=10.2.1
Apple Mac OS X Server=10.3.1
Apple Mac OS X Server=10.0.2
Apple Mac OS X Server=10.1.4
Apple Mac OS X Server=10.5
Apple Mac OS X Server=10.4.7
Apple Mac OS X Server=10.0.1
Apple Mac OS X Server=10.0
Apple Mac OS X Server=10.2.8
Apple Mac OS X Server=10.3.6
Apple Mac OS X Server=10.1.3
Remediation
Patch Available
Patch Available
Event History
Nov 10, 2009
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-2835?
CVE-2009-2835 is classified as a high severity vulnerability, as it allows local users to gain elevated privileges or cause a denial of service.
2
How do I fix CVE-2009-2835?
To fix CVE-2009-2835, upgrade your Apple Mac OS X to version 10.6.2 or later.
3
Who is affected by CVE-2009-2835?
CVE-2009-2835 affects users of Apple Mac OS X versions prior to 10.6.2.
4
What are the potential impacts of CVE-2009-2835?
The impacts of CVE-2009-2835 include privilege escalation, potential data breaches, and system crashes.
5
Is CVE-2009-2835 publicly known?
Yes, CVE-2009-2835 is a publicly disclosed vulnerability that was reported in November 2009.