CVE Vulnerabilities

CVE-2006-1442

Published: May 12, 2006 | Modified: Jul 20, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

The bundle API in CoreFoundation in Apple Mac OS X 10.3.9 and 10.4.6 loads dynamic libraries even if the client application has not directly requested it, which allows attackers to execute arbitrary code from an untrusted bundle.

Affected Software

Name Vendor Start Version End Version
Mac_os_x Apple 10.3.9 (including) 10.3.9 (including)
Mac_os_x Apple 10.4.6 (including) 10.4.6 (including)

References