Secunia Logo
Netsikker nu! 2008
 
CVE Reference: CVE-2006-0396
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2006-0396

Description:
Buffer overflow in Mail in Apple Mac OS X 10.4 up to 10.4.5, when patched with Security Update 2006-001, allows remote attackers to execute arbitrary code via a long Real Name value in an e-mail attachment sent in AppleDouble format, which triggers the overflow when the user double-clicks on an attachment.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/25209

ST
  1015762

SAID
  Secunia Advisory: SA19129

OSVDB
  23872

MISC
  http://www.digitalmunition.com/DMA%5B2006-0313a%5D.txt

CONFIRM
  http://docs.info.apple.com/article.html?artnum=303453

CERT-VN
  980084

BUGTRAQ
  http://www.securityfocus.com/archive/1/archive/1/427601/100/0/threaded

BID
  17081

APPLE
  http://lists.apple.com/archives/security-announce/2006/Mar/msg00001.html


Return to the previous page.