Finder 10.4.6 on Apple Mac OS X 10.4.8 allows user-assisted remote attackers to cause a denial of service and possibly execute arbitrary code via a long volume name in a DMG disk image, which results in memory corruption.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
http://lists.apple.com/archives/Security-announce/2007/Feb/msg00000.html | vendor advisory |
http://www.vupen.com/english/advisories/2007/0140 | vdb entry |
http://www.us-cert.gov/cas/techalerts/TA07-047A.html | third party advisory us government resource |
http://secunia.com/advisories/24198 | third party advisory |
http://www.osvdb.org/32714 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/31410 | vdb entry |
http://www.securityfocus.com/bid/21980 | vdb entry |
http://www.kb.cert.org/vuls/id/240880 | third party advisory us government resource |
http://docs.info.apple.com/article.html?artnum=305102 | |
http://www.securityfocus.com/archive/1/456578/100/0/threaded | mailing list |
http://www.digitalmunition.com/DMA%5B2007-0109a%5D.txt | |
http://projects.info-pull.com/moab/MOAB-09-01-2007.html | exploit |
http://www.securitytracker.com/id?1017662 | vdb entry |