CVE-2006-6353
Description
Mac OS X BOMArchiveHelper crashes when opening a crafted archive, enabling remote denial of service.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Mac OS X BOMArchiveHelper crashes when opening a crafted archive, enabling remote denial of service.
Vulnerability
BOMArchiveHelper in Mac OS X contains multiple unspecified vulnerabilities that cause application crash when processing a crafted archive file. The crashes manifest as KERN_PROTECTION_FAILURE and KERN_INVALID_ADDRESS thread failures. This was discovered through fuzzing with the iSec Partners FileP fuzzer. Affected versions are not explicitly listed, but the vulnerability pertains to Mac OS X systems using BOMArchiveHelper up to the time of disclosure (December 2006) [1].
Exploitation
The attacker must convince a user to open a specially crafted archive file (user-assisted remote attack). No further authentication is required; the crash occurs upon file parsing within BOMArchiveHelper [1].
Impact
Successful exploitation causes the application to crash, resulting in a denial of service (temporary unavailability). There is no indication of code execution or data compromise; the impact is limited to application instability [1].
Mitigation
No official patch or fix has been identified in the available references. As of the publication date (December 2006), users should avoid opening untrusted archive files in applications that rely on BOMArchiveHelper, or use alternative archive utilities. The vulnerability is not listed on CISA's Known Exploited Vulnerabilities (KEV) catalog [1].
AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
4- cpe:2.3:a:apple:bomarchivehelper:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:10.4.8:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:apple:mac_os_x:10.4.8:*:*:*:*:*:*:*
- (no CPE)
- cpe:2.3:o:apple:mac_os_x_server:10.4.8:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- security-protocols.com/2006/12/04/bomarchivehelper-needs-some-lovin/nvdExploitVendor Advisory
- www.securityfocus.com/bid/21446nvdVendor Advisory
News mentions
0No linked articles in our index yet.