Overview
Apple Mail contains a vulnerability that may allow an attacker to execute arbitrary commands on OS X Leopdard (10.5) systems.
Description
Apple OS X uses resource forks to store structured data in files. Data forks are used to store unstructured data. The AppleDouble standard is specified in RFC 1740: |
Impact
A remote, unauthenticated attacker may be able to execute arbitrary commands with the permissions of the user running Apple Mail. |
Solution
We are currently unaware of a practical solution to this problem. |
|
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
- http://www.heise-security.co.uk/news/99257
- http://docs.info.apple.com/article.html?artnum=303382
- http://secunia.com/advisories/27785/
- http://www.us-cert.gov/cas/techalerts/TA06-062A.html
- http://www.cert.org/homeusers/email-attachments.html
- http://www.apple.com/macosx/features/mail.html
- http://tools.ietf.org/html/rfc1740
Acknowledgements
This report was based on publicly available information provided by Heise Security.
This document was written by Ryan Giobbi.
Other Information
CVE IDs: | None |
Severity Metric: | 9.28 |
Date Public: | 2007-11-25 |
Date First Published: | 2007-11-27 |
Date Last Updated: | 2007-11-27 14:06 UTC |
Document Revision: | 33 |