Overview
Apple Safari fails to properly determine file safety, allowing a remote unauthenticated attacker to execute arbitrary commands or code.
Description
Safari Apple Safari is a web browser that comes with the Mac OS X operating system. |
Impact
By convincing a user to view a specially crafted HTML document (for example, a web page), an attacker may be able to execute arbitrary commands or code with the privileges of the user. |
Solution
Install an update |
|
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
- http://docs.info.apple.com/article.html?artnum=303382
- http://docs.info.apple.com/article.html?artnum=303453
- http://www.mathematik.uni-ulm.de/numerik/staff/lehn/macosx.html
- http://www.heise.de/english/newsticker/news/69862
- http://developer.apple.com/documentation/Carbon/Conceptual/LaunchServicesConcepts/LSCConcepts/chapter_2_section_8.html
- http://developer.apple.com/technotes/tn/tn2017.html
- http://developer.apple.com/documentation/mac/MoreToolbox/MoreToolbox-11.html
- http://docs.info.apple.com/article.html?artnum=108009
- http://secunia.com/advisories/18963/
- http://www.securityfocus.com/bid/16736
- http://xforce.iss.net/xforce/xfdb/24808
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0397
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0398
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0399
- http://securitytracker.com/alerts/2006/Feb/1015652.html
Acknowledgements
This vulnerability was publicly disclosed by Michael Lehn.
This document was written by Will Dormann.
Other Information
CVE IDs: | CVE-2006-0848 |
Severity Metric: | 35.44 |
Date Public: | 2006-02-19 |
Date First Published: | 2006-02-21 |
Date Last Updated: | 2006-12-07 16:22 UTC |
Document Revision: | 37 |