CVE-2006-6173 describes a buffer overflow vulnerability in the shared_region_make_private_np function within the vm/vm_unix.c component of Mac OS X 10.4.6 and earlier. This flaw allows local users to execute arbitrary code by manipulating memory allocation through either a small range count or a large number of ranges in the function's parameters. With a CVSS score of 7.2, this vulnerability is rated as high severity, indicating that an attacker with local access can achieve complete confidentiality, integrity, and availability compromise with low attack complexity. While there is no evidence of active exploitation or inclusion in the KEV catalog, an exploit module for local memory corruption is available on ExploitDB. Despite this, the vulnerability has garnered minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 10.4.6CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.