First published: Fri May 12 2006(Updated: )
Integer underflow in CoreFoundation in Apple Mac OS X 10.3.9 and 10.4.6 allows context-dependent attackers to execute arbitrary code via unspecified vectors involving conversions from string to file system representation within (1) CFStringGetFileSystemRepresentation or (2) getFileSystemRepresentation:maxLength:withPath in NSFileManager, and possibly other similar API functions.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
macOS Yosemite | =10.4.6 | |
macOS Yosemite | =10.3.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-1443 is considered a critical vulnerability that allows attackers to execute arbitrary code.
To fix CVE-2006-1443, it is recommended to update Apple Mac OS X to the latest version available that patches this vulnerability.
CVE-2006-1443 affects Apple Mac OS X versions 10.3.9 and 10.4.6.
CVE-2006-1443 may facilitate remote code execution through integer underflow vulnerabilities.
Users of Apple Mac OS X 10.3.9 and 10.4.6 are at risk from CVE-2006-1443 if they are exposed to context-dependent attacks.