Exploitation Summary
EIP tracks 2 public exploits for CVE-2007-6165. PoCs published by Metasploit, heise Security.
AI-analyzed exploit summary This Metasploit module exploits a command execution vulnerability in Mail.app on Mac OS X 10.5.0 by sending a maliciously crafted email with an image attachment containing embedded commands. The exploit leverages AppleDouble encoding to bypass security checks and execute arbitrary payloads.
Description
Mail in Apple Mac OS X Leopard (10.5.1) allows user-assisted remote attackers to execute arbitrary code via an AppleDouble attachment containing an apparently-safe file type and script in a resource fork, which does not warn the user that a separate program is going to be executed. NOTE: this is a regression error related to CVE-2006-0395.
Exploits (2)
This Metasploit module exploits a command execution vulnerability in Mail.app on Mac OS X 10.5.0 by sending a maliciously crafted email with an image attachment containing embedded commands. The exploit leverages AppleDouble encoding to bypass security checks and execute arbitrary payloads.
The provided text is a vulnerability description for CVE-2007-6165, affecting Apple Mac OS X Mail application due to an issue in Launch Services. It lacks actual exploit code, only referencing related CVEs and providing a basic vulnerability summary.