First published: Fri May 12 2006(Updated: )
Finder in Apple Mac OS X 10.3.9 and 10.4.6 allows user-assisted attackers to execute arbitrary code by tricking a user into launching an Internet Location item that appears to use a safe URL scheme, but which actually has a different and more risky scheme.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
macOS Yosemite | =10.4.6 | |
macOS Yosemite | =10.3.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-1448 is classified as a moderate severity vulnerability that allows attackers to execute arbitrary code.
To mitigate CVE-2006-1448, users should avoid opening Internet Location items from untrusted sources and ensure their macOS is updated to the latest version.
CVE-2006-1448 affects Apple Mac OS X versions 10.3.9 and 10.4.6.
CVE-2006-1448 enables user-assisted code execution attacks if a user is tricked into launching a malicious Internet Location item.
Yes, CVE-2006-1448 requires user interaction, as the vulnerability relies on tricking the user into activating the malicious link.