Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2006-1447

Overview

Vulnerability Score 5.0 5.0
CVE Id CVE-2006-1447
Last Modified 07 Mar 2011 09:33:06
Published 12 May 2006 05:02:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact NONE NONE
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2006-1447

Summary

LaunchServices in Apple Mac OS X 10.4.6 allows remote attackers to cause Safari to launch unsafe content via long file name extensions, which prevents Download Validation from determining which application will be used to open the file.

Vulnerable Systems

Operating System

  • Apple Mac Os X 10.4.6


References

CERT - TA06-132A

APPLE - APPLE-SA-2006-05-11

VUPEN - ADV-2006-1779

XF - macos-launchservices-security-bypass(26416)

BID - 17951

OSVDB - 25591

SECTRACK - 1016081

SECUNIA - 20077

Related Patches

Apple 2006-05-11 Security Update 2006-003 Mac OS X 10.4.6 Client (PPC)

Apple 2006-05-11 Security Update 2006-003 Mac OS X 10.4.6 Client (Intel)

Apple 2006-05-11 Security Update 2006-003 (10.4.6 Server)


Last Updated: 27 May 2016 10:42:02