Full Disclosure mailing list archives

Advisory 2006-03-11 Directory Transversal in Apple MacOSX


From: Josh perrymon <perrymonj () networkarmor com>
Date: Sat, 11 Mar 2006 23:00:43 -0800

Advisory 2006-03-11 Directory Transversal in Apple MacOSX

I. BACKGROUND

Advisory marked for immediate release.

II. DESCRIPTION

Remote exploitation of a directory traversal vulnerability in Apple MacOSX could allow attackers to overwrite or view 
arbitrary files with user-supplied contents.

III. HISTORY

This advisory has no history.

IV. WORKAROUND

There are no known workarounds.

V. VENDOR RESPONSE

Apple MacOSX has not commented on this issue.

VI. CVE INFORMATION

The Common Vulnerabilities and Exposures (CVE) project has assigned the
name CVE-2006-442315 to this issue.

APPENDIX A. - Vendor Information
http://www.apple.com/macosx/
APPENDIX B. - References
NONE

CONTACT:
*Josh perrymon bantown () spam la
*1-888-LOL-WHAT
*CISSP GSAE CCE CEH CSFA GREM SSP-CNSA SSP-MPA GIPS GHTQ GWAS


_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Current thread: