Overview
Apple Safari fails to properly determine file safety, allowing a remote unauthenticated attacker to execute arbitrary commands or code.
Description
Safari Apple Safari is a web browser that comes with the Mac OS X operating system.  | 
Impact
By convincing a user to view a specially crafted HTML document (for example, a web page), an attacker may be able to execute arbitrary commands or code with the privileges of the user.   | 
Solution
Install an update  | 
  | 
Vendor Information
CVSS Metrics
| Group | Score | Vector | 
|---|---|---|
| Base | ||
| Temporal | ||
| Environmental | 
References
- http://docs.info.apple.com/article.html?artnum=303382
 - http://docs.info.apple.com/article.html?artnum=303453
 - http://www.mathematik.uni-ulm.de/numerik/staff/lehn/macosx.html
 - http://www.heise.de/english/newsticker/news/69862
 - http://developer.apple.com/documentation/Carbon/Conceptual/LaunchServicesConcepts/LSCConcepts/chapter_2_section_8.html
 - http://developer.apple.com/technotes/tn/tn2017.html
 - http://developer.apple.com/documentation/mac/MoreToolbox/MoreToolbox-11.html
 - http://docs.info.apple.com/article.html?artnum=108009
 - http://secunia.com/advisories/18963/
 - http://www.securityfocus.com/bid/16736
 - http://xforce.iss.net/xforce/xfdb/24808
 - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0397
 - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0398
 - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0399
 - http://securitytracker.com/alerts/2006/Feb/1015652.html
 
Acknowledgements
This vulnerability was publicly disclosed by Michael Lehn.
This document was written by Will Dormann.
Other Information
| CVE IDs: | CVE-2006-0848 | 
| Severity Metric: | 35.44 | 
| Date Public: | 2006-02-19 | 
| Date First Published: | 2006-02-21 | 
| Date Last Updated: | 2006-12-07 16:22 UTC | 
| Document Revision: | 37 |