Apple Mac OS X Metadata Handling Remote Shell Execution Vulnerability
Title : Apple Mac OS X Metadata Handling Remote Shell Execution Vulnerability Advisory ID : FrSIRT/ADV-2006-0671 CVE ID : CVE-2006-0848
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-02-21
A vulnerability has been identified in Apple Mac OS X, which could be exploited by remote attackers to execute arbitrary commands. This flaw is due to an error when processing specially crafted resource forks and HFS meta-data stored in the "__MACOSX" folder (in a ZIP archive) or in email messages with an AppleDouble MIME type, which could be exploited by remote attackers to execute arbitrary shell commands and compromise a vulnerable system by convincing a user to open a malicious email attachment or visit a specially crafted Web page that is designed to automatically exploit this vulnerability through Safari [...]
Subscribe to FrSIRT VNS and receive real-time e-mail and SMS alerts when new vulnerabilities, exploits, or patches relevant to your systems and network configurations are available.
Feedback If you have additional information or corrections for this security advisory please submit them via our contact form or by email to updates@frsirt.com.