The i386_set_ldt system call in the kernel in Apple Mac OS X before 10.6.7 does not properly handle call gates, which allows local users to gain privileges via vectors involving the creation of a call gate entry.
http://support.apple.com/kb/HT4581
http://securityreason.com/securityalert/8402
http://lists.apple.com/archives/security-announce/2011/Mar/msg00006.html