Title: Apple Mac OS X Mail.app Attachment AppleDouble Header Processing Buffer Overflow
Info
Disclosure
Mar 10, 2006
Discovery
Unknown
Dates
Exploit
Mar 14, 2006
Solution
Unknown
Description
A remote overflow exists in Mac OS X Mail.app. The Mail.app facility fails to handle overly long Real Name entries resulting in a buffer overflow. With a specially crafted attachment in the AppleDouble format, an attacker can cause the execution of arbitrary code on a user's system resulting in a loss of integrity and/or availability.
Classification
Location:
Remote / Network Access
Attack Type:
Input Manipulation
Impact:
Loss of Integrity,
Loss of Availability
Exploit:
Exploit Public
Disclosure:
OSVDB Verified
Solution
Currently, there are no known workarounds or upgrades to correct this issue. However, vendor has released a patch to address this vulnerability.