Integer overflow in the searchfs system call in Mac OS X 10.3.9 and earlier allows local users to execute arbitrary code via crafted parameters.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2005-0973
http://www.kb.cert.org/vuls/id/185702
http://lists.apple.com/archives/security-announce/2005/Apr/msg00000.html