iDEFENSE Security Advisory 03.21.05 - Local exploitation of a buffer overflow vulnerability within the Core Foundation Library included by default in Apple Computer Inc.'s Mac OS X could allow an attacker to gain root privileges. iDEFENSE has confirmed this vulnerability in Mac OS X 10.3.5 and Mac OS X 10.3.6. Earlier versions are suspected vulnerable.
db5ff37bdf6a8f47915914d8f018372251de8b3a79547f3275e8348007440d4a
Local root exploit for /usr/bin/su on Mac OS X that makes use of the buffer overflow vulnerability discovered by iDefense using the CF_CHARSET_PATH environment variable.
3d4f65ef5c5787a4e22d1adaf440941026368d42080a9637123986b999b4dcbf