PT-2004-1604 · Apple · Macos X+1
Lixlpixel
·
Publicado
2004-05-28
·
Atualizado
2017-07-11
·
CVE-2004-0486
CVSS v2.0
7.6
Alta
| Vetor | AV:N/AC:H/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Mac OS X versions 10.2.8 through 10.3.3
Description
The issue allows attackers to execute arbitrary code by processing scripts that it did not initiate. Originally reported as a directory traversal vulnerability, it can be exploited through the Safari web browser using the
runscript parameter in a help: URI handler.Recommendations
For Mac OS X versions 10.2.8 through 10.3.3, consider disabling the HelpViewer functionality until a patch is available to prevent the execution of arbitrary code. Restrict access to the
help: URI handler to minimize the risk of exploitation. Avoid using the runscript parameter in the Safari web browser until the issue is resolved.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Macos X
Safari