Integer underflow in CoreFoundation in Apple Mac OS X 10.3.9 and 10.4.6 allows context-dependent attackers to execute arbitrary code via unspecified vectors involving conversions from string to file system representation within (1) CFStringGetFileSystemRepresentation or (2) getFileSystemRepresentation:maxLength:withPath in NSFileManager, and possibly other similar API functions.
| Software | From | Fixed in |
|---|---|---|
| apple / mac_os_x | 10.4.6 | 10.4.6.x |
| apple / mac_os_x | 10.3.9 | 10.3.9.x |