PT-2004-1603 · Apple · Macos X
Kang
·
Publicado
2004-05-28
·
Atualizado
2017-07-11
·
CVE-2004-0485
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Mac OS X versions 10.2.8 through 10.3.3
Description
The issue allows remote attackers to write arbitrary files by causing a disk image file (.dmg) to be mounted as a disk volume, due to the default protocol helper for the disk: URI.
Recommendations
For Mac OS X versions 10.2.8 through 10.3.3, consider disabling the default protocol helper for the disk: URI as a temporary workaround until a patch is available. Restrict access to mounting disk image files (.dmg) to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Macos X