First published: Fri May 12 2006(Updated: )
The bundle API in CoreFoundation in Apple Mac OS X 10.3.9 and 10.4.6 loads dynamic libraries even if the client application has not directly requested it, which allows attackers to execute arbitrary code from an untrusted bundle.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
macOS Yosemite | =10.4.6 | |
macOS Yosemite | =10.3.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-1442 is considered a critical vulnerability as it allows arbitrary code execution from untrusted bundles.
To mitigate CVE-2006-1442, ensure that you update your system to the latest version of Mac OS X that contains security patches.
CVE-2006-1442 affects Mac OS X versions 10.3.9 and 10.4.6.
Attackers could exploit CVE-2006-1442 to execute arbitrary code on the user's system via untrusted dynamic libraries.
Disabling the loading of dynamic libraries from untrusted sources can serve as a temporary workaround for CVE-2006-1442.