Stack-based buffer overflow in the semop system call in Mac OS X 10.3.9 and earlier allows local users to gain privileges via crafted arguments.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2005-0972
http://www.kb.cert.org/vuls/id/212190
http://lists.apple.com/archives/security-announce/2005/Apr/msg00000.html