Security Update 2006-002
- 0
- Add a Comment
- No Related Post
Critical: Extremely critical
Impact: Security Bypass, System access
Where: From remote
Apple has issued a security update for Mac OS X, which fixes multiple vulnerabilities.
1) Under certain circumstances, it is possible for JavaScript to bypass the same-origin policy via specially crafted archives.
2) A boundary error in Mail can be exploited to cause a buffer overflow via a specially crafted email. This allows execution of arbitrary code on a user’s system if a specially crafted attachment is double-clicked.
3) An error in Safari / LaunchServices can cause a malicious application to appear as a safe file type. This may cause a malicious file to be executed automatically when visiting a malicious web site.
[Continue reading Secunia Advisory SA19129]
