PT-2008-1713 · Apple · Safari+3
Publicado
2008-03-18
·
Atualizado
2017-08-08
·
CVE-2008-0052
CVSS v2.0
6.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
CoreServices in Apple Mac OS X version 10.4.11
Description
The issue allows remote attackers to force Safari users into opening an .ief file in AppleWorks, even when the "Open 'Safe' files" preference is set, because CoreServices treats .ief as a safe file type.
Recommendations
For CoreServices in Apple Mac OS X version 10.4.11, consider changing the file type association for .ief files to prevent them from being opened in AppleWorks by default, as a temporary workaround until a patch is available.
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Appleworks
Coreservices
Macos X
Safari