PT-2004-1604 · Apple · Macos X+1

Lixlpixel

·

Published

2004-05-28

·

Updated

2017-07-11

·

CVE-2004-0486

CVSS v2.0

7.6

High

VectorAV:N/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Mac OS X versions 10.2.8 through 10.3.3
Description The issue allows attackers to execute arbitrary code by processing scripts that it did not initiate. Originally reported as a directory traversal vulnerability, it can be exploited through the Safari web browser using the runscript parameter in a help: URI handler.
Recommendations For Mac OS X versions 10.2.8 through 10.3.3, consider disabling the HelpViewer functionality until a patch is available to prevent the execution of arbitrary code. Restrict access to the help: URI handler to minimize the risk of exploitation. Avoid using the runscript parameter in the Safari web browser until the issue is resolved.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-0486

Affected Products

Macos X
Safari