Apple Mac OS X Archive Metadata Command Execution Vulnerability
BID:16736
Info
Apple Mac OS X Archive Metadata Command Execution Vulnerability
| Bugtraq ID: | 16736 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2006-0397 CVE-2006-0398 CVE-2006-0399 CVE-2006-0848 CVE-2006-0394 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 21 2006 12:00AM |
| Updated: | Jul 06 2016 02:40PM |
| Credit: | Discovered by Michael Lehn. |
| Vulnerable: |
Apple Mac OS X Server 10.4.5 Apple Mac OS X Server 10.3.9 Apple Mac OS X 10.4.5 Apple Mac OS X 10.3.9 |
| Not Vulnerable: | |
Discussion
Apple Mac OS X Archive Metadata Command Execution Vulnerability
Apple Mac OS X is prone to an arbitrary command-execution vulnerability when processing metadata in archive files. Commands would be executed in the context of the user opening the archive file.
Attackers can reportedly use Safari and Apple Mail as exploitation vectors for this vulnerability.
Mac OS X 10.4.5 is reported to be vulnerable. Earlier versions may also be affected.
Apple Mac OS X is prone to an arbitrary command-execution vulnerability when processing metadata in archive files. Commands would be executed in the context of the user opening the archive file.
Attackers can reportedly use Safari and Apple Mail as exploitation vectors for this vulnerability.
Mac OS X 10.4.5 is reported to be vulnerable. Earlier versions may also be affected.
Exploit / POC
Apple Mac OS X Archive Metadata Command Execution Vulnerability
The safari_safefiles_exec.pm exploit is available for the Metasploit framework.
http://www.securityfocus.com/data/vulnerabilities/exploits/safari_safefiles_exec.pm
The safari_safefiles_exec.pm exploit is available for the Metasploit framework.
http://www.securityfocus.com/data/vulnerabilities/exploits/safari_safefiles_exec.pm
Solution / Fix
Apple Mac OS X Archive Metadata Command Execution Vulnerability
Solution:
Apple has released security advisory APPLE-SA-2006-03-01 to address this issue. Apple has also released security advisory APPLE-SA-2006-03-13 with further updates to address this issue.
Apple Mac OS X 10.3.9
Apple Mac OS X Server 10.3.9
Apple Mac OS X Server 10.4.5
Apple Mac OS X 10.4.5
Solution:
Apple has released security advisory APPLE-SA-2006-03-01 to address this issue. Apple has also released security advisory APPLE-SA-2006-03-13 with further updates to address this issue.
Apple Mac OS X 10.3.9
-
Apple SecUpd2006-001Pan.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=09857&cat= 1&platform=osx&method=sa/SecUpd2006-001Pan.dmg
Apple Mac OS X Server 10.3.9
-
Apple SecUpdSrvr2006-001Pan.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=09858&cat= 1&platform=osx&method=sa/SecUpdSrvr2006-001Pan.dmg
Apple Mac OS X Server 10.4.5
-
Apple SecUpd2006-001Intel.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=09822&cat= 1&platform=osx&method=sa/SecUpd2006-001Intel.dmg -
Apple SecUpd2006-001Ti.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=09818&cat= 1&platform=osx&method=sa/SecUpd2006-001Ti.dmg
Apple Mac OS X 10.4.5
References
Apple Mac OS X Archive Metadata Command Execution Vulnerability
References:
References:
- Apple Security Updates (Apple)
- Mac OS X Homepage (Apple)
- Security Update 2006-002 (Apple)