|
|
|
View Notes By
|
|
|
|
Other Documents
|
|
|
|
|
Apple Computer Inc. Information for VU#650937
| Date Notified | 01/20/2003 |
| Date Modified | 08/20/2003 04:12:16 PM |
| Status Summary | Vulnerable |
Vendor StatementApple: Not Vulnerable. The underlying code in Mac OS X is not susceptible to the vulnerability described in this notice.US-CERT AddendumBased on source code analysis, cvs-29 from the Darwin Projects Directory appears to be vulnerable. However, the Apple OS X malloc(3) implementation (phkmalloc) may safely handle the double-free condition. If malloc(3) is configured such that all warnings are fatal ("A" option), the impact of this vulnerability on Darwin cvs-29 may be limited to a denial of service.
Darwin cvs-29 may not be the same cvs code that is shipped with the Apple OS X Developer Tools package.
If you have feedback, comments, or additional information about this vulnerability, please send us
email.
|
 |