Skip navigation.

exploreopera

| Help

Sign up | Help

For a Cool Web Surfing

Alerts, News, Tests, Scan Online, Threats... and more !

Apple Mac OS : Highly Critical Vulnerability

, , , , ,

Apple Mac OS X UDIF Memory Corruption Vulnerability

- Highly critical - From remote

Issued 1 day ago. Updated 12 hours ago.

LMH has reported a vulnerability in Mac OS X, which potentially can be exploited by malicious, local users to gain escalated privileges or by malicious people to compromise a vulnerable system.


Secunia Advisory: SA23012

Release Date: 2006-11-21

Last Update: 2006-11-22

Critical: Highly critical

Impact: Privilege escalation

DoS

System access

Where: From remote

Solution Status: Unpatched

OS: Apple Macintosh OS X

CVE reference: CVE-2006-6061 (Secunia mirror)

CVE-2006-6062 (Secunia mirror)

This advisory is currently marked as unpatched! - Companies can be alerted when a patch is released!

Description:

LMH has reported a vulnerability in Mac OS X, which potentially can be exploited by malicious, local users to gain escalated privileges or by malicious people to compromise a vulnerable system.

The vulnerability is caused due to an error in com.apple.AppleDiskImageController when handling corrupted DMG image structures. This can be exploited to cause a memory corruption and may allow execution of arbitrary code in kernel-mode.

The vulnerability is reported in a fully patched Mac OS X (2006-11-20). Other versions may also be affected.

Solution:

Deactivate the option "opening safe files after downloading" in the preferences and grant only trusted users access to affected systems.

Is Vista security a selling point?Brain, the first virus appears 21 years ago in January 2007 !

Write a comment

You must be logged in to write a comment. if you're not a registered member, please sign up.

July 2008
SMTWTFS
June 2008August 2008
12345
6789101112
13141516171819
20212223242526
2728293031