Mac OS X DMG Image Validation Error May Let Remote Users Execute Arbitrary Code
|
|
SecurityTracker Alert ID: 1017260
|
|
SecurityTracker URL: http://securitytracker.com/id?1017260
|
|
CVE Reference: CVE-2006-6061
(Links to External Site)
|
Updated: Nov 23 2006
|
Original Entry Date: Nov 21 2006
|
Impact: Execution of arbitrary code via network, User access via network
|
Exploit Included: Yes
|
Description: A vulnerability was reported in Mac OS X. A remote user can obtain privileges on the target system.
The com.apple.AppleDiskImageController does not properly validate DMG files. A user can create a specially crafted DMG image that,
when loaded by the target user, will trigger a memory corruption error and execute arbitrary code on the target system.
LMH discovered
this vulnerability.
The original advisory is available at:
http://projects.info-pull.com/mokb/MOKB-20-11-2006.html
|
Impact: A remote user can create a DMG image file that, when loaded by the target user, will execute arbitrary code on the target user's system.
|
Solution: No solution was available at the time of this entry.
|
Vendor URL: www.apple.com/ (Links to External Site)
|
Cause: Access control error
|
Underlying OS: UNIX (Mac OS X)
|
|
Message History:
None.
|
Source Message Contents
|
Date: Mon, 20 Nov 2006 23:58:06 -0500
Subject: Mac OS X Apple UDIF Disk Image Kernel Memory Corruption (1)
|
http://projects.info-pull.com/mokb/MOKB-20-11-2006.html
|
|