Back to search
CVE-2006-6061
Published: Nov 22, 2006
Modified: Aug 7, 2024
PUBLISHED
Description
com.apple.AppleDiskImageController in Apple Mac OS X 10.4.8, and possibly other versions, allows remote attackers to execute arbitrary code via a malformed DMG image that triggers memory corruption. NOTE: the severity of this issue has been disputed by a third party, who states that the impact is limited to a denial of service (kernel panic) due to a vm_fault call with a non-aligned address.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
http://alastairs-place.net/2006/11/dmg-vulnerability/
x_refsource_MISC
TA07-072A
third-party-advisory
x_refsource_CERT
APPLE-SA-2007-03-13
vendor-advisory
x_refsource_APPLE
http://docs.info.apple.com/article.html?artnum=305214
x_refsource_CONFIRM
1017751
vdb-entry
x_refsource_SECTRACK
23012
third-party-advisory
x_refsource_SECUNIA
ADV-2006-4629
vdb-entry
x_refsource_VUPEN
30509
vdb-entry
x_refsource_OSVDB
http://projects.info-pull.com/mokb/MOKB-20-11-2006.html
x_refsource_MISC
VU#367424
third-party-advisory
x_refsource_CERT-VN
ADV-2007-0930
vdb-entry
x_refsource_VUPEN
1017260
vdb-entry
x_refsource_SECTRACK
21201
vdb-entry
x_refsource_BID
macosx-dmg-code-execution(30440)
vdb-entry
x_refsource_XF
24479
third-party-advisory
x_refsource_SECUNIA
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now