Event Monitor in Apple Mac OS X before 10.6.3 does not...
High severity
Unreviewed
Published
May 2, 2022
to the GitHub Advisory Database
•
Updated Feb 1, 2023
Description
Published by the National Vulnerability Database
Mar 30, 2010
Published to the GitHub Advisory Database
May 2, 2022
Last updated
Feb 1, 2023
Event Monitor in Apple Mac OS X before 10.6.3 does not properly validate hostnames of SSH clients, which allows remote attackers to cause a denial of service (arbitrary client blacklisting) via a crafted DNS PTR record, related to a "plist injection issue."
References