Launch Services in Apple Mac OS X 10.6.x before 10.6.2 recursively clears quarantine information upon opening a quarantined folder, which allows user-assisted remote attackers to execute arbitrary code via a quarantined application that does not trigger a potentially unsafe warning message.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Mac_os_x | Apple | 10.6 (including) | 10.6 (including) |
Mac_os_x | Apple | 10.6.1 (including) | 10.6.1 (including) |