CVE-2001-1411 describes a format string vulnerability in the gm4 (m4) utility on Apple Mac OS X. This flaw could allow local users to gain elevated privileges if gm4 is invoked by setuid programs. With a CVSS score of 7.2, this vulnerability is considered high severity due to its local attack vector, low attack complexity, and complete compromise of confidentiality, integrity, and availability. While there is no evidence of active exploitation, nor publicly available exploit code in Metasploit, Nuclei, or ExploitDB, the vulnerability has garnered significant community discussion, indicating awareness among security researchers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
10.4.9CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:10.4.9:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.