Launch Services in Apple Mac OS X 10.6.x before 10.6.2 recursively clears quarantine information upon opening a quarantined folder, which allows user-assisted remote attackers to execute arbitrary code via a quarantined application that does not trigger a "potentially unsafe" warning message.
| Software | From | Fixed in |
|---|---|---|
| apple / mac_os_x | 10.6 | 10.6.x |
| apple / mac_os_x | 10.6.1 | 10.6.1.x |
| apple / mac_os_x_server | 10.6 | 10.6.x |
| apple / mac_os_x_server | 10.6.1 | 10.6.1.x |