>> Apple Mac OS X Mail Attachment Handling Command Injection Vulnerability
Title : Apple Mac OS X Mail Attachment Handling Command Injection Vulnerability VUPEN ID : VUPEN/ADV-2007-3958 CVE ID : CVE-2007-6165
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-11-22
Technical Description
A vulnerability has been identified in Apple Mac OS X, which could be exploited by remote attackers or malware to compromise a vulnerable system. This issue is caused by an error in the Mail application that does not properly validate file types before being opened, which could be exploited by attackers to execute arbitrary shell commands by tricking a user into opening a specially crafted email attachment with a trusted file extension (e.g. JPG).