Vulnerability Name: | CVE-2006-1442 (CCN-26407) | ||||||||
Assigned: | 2006-05-11 | ||||||||
Published: | 2006-05-11 | ||||||||
Updated: | 2017-07-20 | ||||||||
Summary: | The bundle API in CoreFoundation in Apple Mac OS X 10.3.9 and 10.4.6 loads dynamic libraries even if the client application has not directly requested it, which allows attackers to execute arbitrary code from an untrusted bundle. This vulnerability is addressed in the following product release: Apple, Mac OS X, 10.4.6 (2006-003) | ||||||||
CVSS v3 Severity: | 5.5 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||
References: | Source: MITRE Type: CNA CVE-2006-1442 Source: CCN Type: Apple Security Update 2006-003 About Security Update 2006-003 Source: APPLE Type: Patch APPLE-SA-2006-05-11 Source: CCN Type: SA20077 Mac OS X Security Update Fixes Multiple Vulnerabilities Source: SECUNIA Type: UNKNOWN 20077 Source: CCN Type: SECTRACK ID: 1016080 Apple Mac OS X CoreFoundation Untrusted Bundles or the CFStringGetFileSystemRepresentation() API May Let Users Execute Arbitrary Code Source: SECTRACK Type: UNKNOWN 1016080 Source: OSVDB Type: UNKNOWN 25586 Source: CCN Type: OSVDB ID: 25586 Apple Mac OS X CoreFoundation Untrusted Bundle Arbitrary Code Execution Source: BID Type: UNKNOWN 17951 Source: CCN Type: BID-17951 Apple Mac OS X Security Update 2006-003 Multiple Vulnerabilities Source: CCN Type: US-CERT Technical Cyber Security Alert TA06-132A Apple Mac Products Affected by Multiple Vulnerabilities Source: CERT Type: US Government Resource TA06-132A Source: VUPEN Type: UNKNOWN ADV-2006-1779 Source: XF Type: UNKNOWN macos-corefoundation-bundle-code-execution(26407) Source: XF Type: UNKNOWN macos-corefoundation-bundle-code-execution(26407) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |