Secunia Logo
Netsikker nu! 2008
 
Mac OS X Security Update Fixes Multiple Vulnerabilities
Secunia Advisory: SA19129
Release Date: 2006-03-14
Last Update: 2006-03-17
Popularity: 17,287 views

Critical:
Extremely critical
Impact: Security Bypass
System access
Where: From remote
Solution Status: Vendor Patch

OS:Apple Macintosh OS X

Subscribe: Instant alerts on relevant vulnerabilities

CVE reference:CVE-2006-0396
CVE-2006-0397
CVE-2006-0398
CVE-2006-0399
CVE-2006-0400


Description:
Apple has issued a security update for Mac OS X, which fixes multiple vulnerabilities.

1) Under certain circumstances, it is possible for JavaScript to bypass the same-origin policy via specially crafted archives.

2) A boundary error in Mail can be exploited to cause a buffer overflow via a specially crafted email with an overly long Real Name entry. This allows execution of arbitrary code on a user's system if a specially crafted attachment in the AppleDouble format is double-clicked.

3) An error in Safari / LaunchServices can cause a malicious application to appear as a safe file type. This may cause a malicious file to be executed automatically when visiting a malicious web site.

This vulnerability is related to:
SA18963

Solution:
Apply Security Update 2006-002.

Mac OS X 10.4.5 (PPC):
http://www.apple.com/support/download...ityupdate2006002v11macosx1045ppc.html

Mac OS X 10.4.5 Client (Intel):
http://www.apple.com/support/download...e2006002v11macosx1045clientintel.html

Mac OS X 10.3.9 Client:
http://www.apple.com/support/downloads/securityupdate20060021039client.html

Mac OS X 10.3.9 Server:
http://www.apple.com/support/downloads/securityupdate20060021039server.html

Provided and/or discovered by:
2) Kevin Finisterre, DigitalMunition.
3) The vendor credits Will Dormann and Andris Baumberger.

Changelog:
2006-03-14: Added information provided by Kevin Finisterre.
2006-03-16: Vendor issues updated Security Update for version 10.4.5.
2006-03-17: Added link to US-CERT vulnerability note.

Original Advisory:
Apple:
http://docs.info.apple.com/article.html?artnum=303453

Kevin Finisterre:
http://www.digitalmunition.com/DMA%5B2006-0313a%5D.txt

Other References:
SA18963:
http://secunia.com/advisories/18963/

US-CERT VU#980084:
http://www.kb.cert.org/vuls/id/980084


Track this Secunia Advisory
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.

Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.

About this Secunia Advisory
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
  
Latest Advisories

Send Feedback to Secunia
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.

Most Popular - 3 Hours

1. phpBB Avatar Functions Information Disclosure and Deletion // 127 views
2. phpBB Avatar Script Insertion Vulnerability // 112 views
3. phpBB "url" bbcode Script Insertion Vulnerability // 100 views
4. phpBB BBcode "url" Script Insertion Vulnerability // 79 views
5. ArticleBeach Script "page" File Inclusion Vulnerability // 63 views
6. Sun Java System Web Proxy Server FTP Subsystem Buffer Overflow // 35 views
7. Apple Mac OS X Security Update Fixes Multiple Vulnerabilities // 33 views
8. DFF PHP Framework API "DFF_config[dir_include]" File Inclusion Vulnerabilities // 27 views
9. CA ARCserve Backup Multiple Vulnerabilities // 27 views
10. CUPS Multiple Vulnerabilities // 25 views