Apple has released security updates to address multiple vulnerabilities identified in Mac OS X. These flaws could be exploited by remote attackers to execute arbitrary commands or bypass security restrictions.
The first issue is due to an error when loading documents containing specially crafted Javascript code, which could be exploited by malicious web sites to bypass the same-origin policy restrictions and access arbitrary data.
The second flaw is due to a buffer overflow error in Mail when handling specially crafted attachments, which could be exploited by remote attackers to execute arbitrary commands by convincing a user to double-click on a malicious attachment within Mail.
The third vulnerability is due to errors within the validation of file types in Safari and LaunchServices, which could be exploited by attackers to execute arbitrary commands, via a malicious shell script masqueraded as a safe file type. This vulnerability is a variant of VUPEN/ADV-2006-0671
Note : Various regressions caused by Security Update 2006-001 have also been identified in "apache_mod_php" and "rsync".