CVE-2009-2829

Severity CVSS v4.0:
Pending analysis
Type:
CWE-255 Credentials Management
Publication date:
10/11/2009
Last modified:
09/04/2025

Description

Event Monitor in Apple Mac OS X 10.5.8 does not properly handle crafted authentication data sent to an SSH daemon, which allows remote attackers to cause a denial of service via vectors involving processing of XML log documents by other services, related to a "log injection" issue.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:apple:mac_os_x_server:10.5.8:*:*:*:*:*:*:*