vendor:
Mail.app
by:
Kevin Finisterre
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Mail.app
Affected Version From: 2.0.7 (746.2)
Affected Version To: 2.0.7 (746.2)
Patch Exists: YES
Related CWE: N/A
CPE: a:apple:mail.app
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: OSX 10.4.5 Build 8H14 + Security Update 2006-001 (PowerPC) v1.0
2006
RFC-1740 MIME-based Mac file buffer overflow
A buffer overflow vulnerability exists in Mail.app Version 2.0.7 (746.2) on OSX 10.4.5 Build 8H14 + Security Update 2006-001 (PowerPC) v1.0. The vulnerability is triggered when a specially crafted AppleSingle file header is sent to the application. The file header contains a 4 byte magic number, 4 byte version number, 16 bytes of filler, 2 byte number of entries, and Entry descriptors for each Entry. The Entry descriptor contains a 4 byte entry id, 4 byte offset, and 4 byte length. The Real Name entry id is 0x03, Finder Info is 0x09 and Resource Fork is 0x02. An attacker can exploit this vulnerability to execute arbitrary code on the target system.
Mitigation:
Users should update to the latest version of Mail.app.