SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information

Report a Vulnerability

 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

Vulnerability Note VU#180692

Apple Mac OS X AFP server vulnerable to DoS via maliciously-crafted AFP request

Overview

A vulnerability in the Apple Mac OS X AFP server may allow an attacker to cause a denial-of-service condition on an affected system.

I. Description

The AFP (Apple Filing Protocol) service allows Apple Mac OS clients to access files remotely from a server. Apple's Mac OS X AFP server contains an unchecked error condition. When file sharing is enabled, a remote attacker can exploit this vulnerability by sending a specially crafted invalid AFP request. This crafted AFP request may cause the service to crash, resulting in a denial-of-service condition. Apple states that any Mac OS X system with AFP server enabled is vulnerable; however, AFP server is not enabled by default on Apple Mac OS X.

II. Impact

When file sharing is enabled, a maliciously crafted AFP request may cause the AFP server to crash, resulting in a denial-of-service condition.

III. Solution

Apply an update

Apple has addressed this issue in Security Update 2006-004.
Workaround

Disable file sharing if it is not required. File sharing can be disabled in the "Sharing" settings of system preferences.

Systems Affected

VendorStatusDate NotifiedDate Updated
Apple Computer, Inc.Vulnerable4-Aug-2006

References

http://docs.info.apple.com/article.html?artnum=304063
http://secunia.com/advisories/21253/

Credit

Thanks to Apple Product Security for reporting this vulnerability.

This document was written by Katie Washok.

Other Information

Date Public:2006-08-01
Date First Published:2006-08-04
Date Last Updated:2006-09-18
CERT Advisory: 
CVE-ID(s):CVE-2006-3496
NVD-ID(s):CVE-2006-3496
US-CERT Technical Alerts: 
Severity Metric:0.81
Document Revision:21

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Produced 2006 by US-CERT, a government organization
Disclaimers and copyright information
Get a PDF Reader