CVE-2006-5710
The Airport driver for certain Orinoco based Airport cards in Darwin kernel 8.8.0 in Apple Mac OS X 10.4.8, and possibly other versions, allows remote attackers to execute arbitrary code via an 802.11 probe response frame without any valid information…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 18.5%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
The Airport driver for certain Orinoco based Airport cards in Darwin kernel 8.8.0 in Apple Mac OS X 10.4.8, and possibly other versions, allows remote attackers to execute arbitrary code via an 802.11 probe response frame without any valid information element (IE) fields after the header, which triggers a heap-based buffer overflow.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 18.52% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- apple/mac os x · opendarwin/darwin kernel
- Source
- cve@mitre.org
References
- http://docs.info.apple.com/article.html?artnum=304829
- http://lists.apple.com/archives/security-announce/2006/Nov/msg00001.html
- http://projects.info-pull.com/mokb/MOKB-01-11-2006.htmlExploit
- http://secunia.com/advisories/22679Exploit, Vendor Advisory
- http://secunia.com/advisories/23155
- http://securitytracker.com/id?1017151
- http://www.kb.cert.org/vuls/id/191336US Government Resource
- http://www.osvdb.org/30180
- http://www.securityfocus.com/bid/20862Exploit
- http://www.us-cert.gov/cas/techalerts/TA06-333A.htmlUS Government Resource
- http://www.vupen.com/english/advisories/2006/4313Vendor Advisory
- http://www.vupen.com/english/advisories/2006/4750Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/29965
- http://docs.info.apple.com/article.html?artnum=304829
- http://lists.apple.com/archives/security-announce/2006/Nov/msg00001.html
- http://projects.info-pull.com/mokb/MOKB-01-11-2006.htmlExploit
- http://secunia.com/advisories/22679Exploit, Vendor Advisory
- http://secunia.com/advisories/23155
- http://securitytracker.com/id?1017151
- http://www.kb.cert.org/vuls/id/191336US Government Resource
- http://www.osvdb.org/30180
- http://www.securityfocus.com/bid/20862Exploit
- http://www.us-cert.gov/cas/techalerts/TA06-333A.htmlUS Government Resource
- http://www.vupen.com/english/advisories/2006/4313Vendor Advisory
- http://www.vupen.com/english/advisories/2006/4750Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/29965
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.