Description: LMH has reported a vulnerability in Mac OS X, which can potentially be exploited by malicious people to compromise a user's system.
The vulnerability is caused due to an integer overflow error in the "ffs_mountfs()" function when handling UFS filesystem disc images. This can be exploited to cause a heap-based buffer overflow via a specially crafted UFS DMG image.
Successful exploitation may allow the execution of arbitrary code.
NOTE: This is only remotely exploitable via the Safari web browser when the "opening safe files after downloading" option is enabled.
The vulnerability is reported in an updated Mac OS X 10.4.8. Other versions may also be affected.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.