Secunia Logo
 
CVE Reference: CVE-2006-1442
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2006-1442

Description:
The bundle API in CoreFoundation in Apple Mac OS X 10.3.9 and 10.4.6 loads dynamic libraries even if the client application has not directly requested it, which allows attackers to execute arbitrary code from an untrusted bundle.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/26407

ST
  1016080

SAID
  Secunia Advisory: SA20077

OSVDB
  25586

CERT
  http://www.us-cert.gov/cas/techalerts/TA06-132A.html

BID
  17951

APPLE
  http://lists.apple.com/archives/security-announce/2006/May/msg00003.html


Return to the previous page.