CVE-2006-6061

com.apple.AppleDiskImageController in Apple Mac OS X 10.4.8, and possibly other versions, allows remote attackers to execute arbitrary code via a malformed DMG image that triggers memory corruption. NOTE: the severity of this issue has been disputed by a third party, who states that the impact is limited to a denial of service (kernel panic) due to a vm_fault call with a non-aligned address.
References
Link Resource
http://alastairs-place.net/2006/11/dmg-vulnerability/
http://docs.info.apple.com/article.html?artnum=305214
http://kernelfun.blogspot.com/2006/11/more-mokb-20-11-2006-related-news.html
http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html
http://projects.info-pull.com/mokb/MOKB-20-11-2006.html Exploit Vendor Advisory
http://secunia.com/advisories/23012 Vendor Advisory
http://secunia.com/advisories/24479
http://securitytracker.com/id?1017260
http://www.kb.cert.org/vuls/id/367424 US Government Resource
http://www.matasano.com/log/633/alastair-houghton-debunks-lmh-mokb-finding/
http://www.osvdb.org/30509
http://www.securityfocus.com/bid/21201 Exploit
http://www.securitytracker.com/id?1017751
http://www.us-cert.gov/cas/techalerts/TA07-072A.html US Government Resource
http://www.vupen.com/english/advisories/2006/4629
http://www.vupen.com/english/advisories/2007/0930
https://exchange.xforce.ibmcloud.com/vulnerabilities/30440
http://alastairs-place.net/2006/11/dmg-vulnerability/
http://docs.info.apple.com/article.html?artnum=305214
http://kernelfun.blogspot.com/2006/11/more-mokb-20-11-2006-related-news.html
http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html
http://projects.info-pull.com/mokb/MOKB-20-11-2006.html Exploit Vendor Advisory
http://secunia.com/advisories/23012 Vendor Advisory
http://secunia.com/advisories/24479
http://securitytracker.com/id?1017260
http://www.kb.cert.org/vuls/id/367424 US Government Resource
http://www.matasano.com/log/633/alastair-houghton-debunks-lmh-mokb-finding/
http://www.osvdb.org/30509
http://www.securityfocus.com/bid/21201 Exploit
http://www.securitytracker.com/id?1017751
http://www.us-cert.gov/cas/techalerts/TA07-072A.html US Government Resource
http://www.vupen.com/english/advisories/2006/4629
http://www.vupen.com/english/advisories/2007/0930
https://exchange.xforce.ibmcloud.com/vulnerabilities/30440
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:apple:mac_os_x:10.4.8:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x_server:10.4.8:*:*:*:*:*:*:*

History

21 Nov 2024, 00:21

Type Values Removed Values Added
References () http://alastairs-place.net/2006/11/dmg-vulnerability/ - () http://alastairs-place.net/2006/11/dmg-vulnerability/ -
References () http://docs.info.apple.com/article.html?artnum=305214 - () http://docs.info.apple.com/article.html?artnum=305214 -
References () http://kernelfun.blogspot.com/2006/11/more-mokb-20-11-2006-related-news.html - () http://kernelfun.blogspot.com/2006/11/more-mokb-20-11-2006-related-news.html -
References () http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html - () http://lists.apple.com/archives/security-announce/2007/Mar/msg00002.html -
References () http://projects.info-pull.com/mokb/MOKB-20-11-2006.html - Exploit, Vendor Advisory () http://projects.info-pull.com/mokb/MOKB-20-11-2006.html - Exploit, Vendor Advisory
References () http://secunia.com/advisories/23012 - Vendor Advisory () http://secunia.com/advisories/23012 - Vendor Advisory
References () http://secunia.com/advisories/24479 - () http://secunia.com/advisories/24479 -
References () http://securitytracker.com/id?1017260 - () http://securitytracker.com/id?1017260 -
References () http://www.kb.cert.org/vuls/id/367424 - US Government Resource () http://www.kb.cert.org/vuls/id/367424 - US Government Resource
References () http://www.matasano.com/log/633/alastair-houghton-debunks-lmh-mokb-finding/ - () http://www.matasano.com/log/633/alastair-houghton-debunks-lmh-mokb-finding/ -
References () http://www.osvdb.org/30509 - () http://www.osvdb.org/30509 -
References () http://www.securityfocus.com/bid/21201 - Exploit () http://www.securityfocus.com/bid/21201 - Exploit
References () http://www.securitytracker.com/id?1017751 - () http://www.securitytracker.com/id?1017751 -
References () http://www.us-cert.gov/cas/techalerts/TA07-072A.html - US Government Resource () http://www.us-cert.gov/cas/techalerts/TA07-072A.html - US Government Resource
References () http://www.vupen.com/english/advisories/2006/4629 - () http://www.vupen.com/english/advisories/2006/4629 -
References () http://www.vupen.com/english/advisories/2007/0930 - () http://www.vupen.com/english/advisories/2007/0930 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/30440 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/30440 -

Information

Published : 2006-11-22 01:07

Updated : 2024-11-21 00:21


NVD link : CVE-2006-6061

Mitre link : CVE-2006-6061

CVE.ORG link : CVE-2006-6061


JSON object : View

Products Affected

apple

  • mac_os_x
  • mac_os_x_server