PT-2004-1604 · Apple · Macos X+1
Lixlpixel
·
Published
2004-05-28
·
Updated
2017-07-11
·
CVE-2004-0486
CVSS v2.0
7.6
High
| Vector | AV:N/AC:H/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Mac OS X versions 10.2.8 through 10.3.3
Description
The issue allows attackers to execute arbitrary code by processing scripts that it did not initiate. Originally reported as a directory traversal vulnerability, it can be exploited through the Safari web browser using the
runscript parameter in a help: URI handler.Recommendations
For Mac OS X versions 10.2.8 through 10.3.3, consider disabling the HelpViewer functionality until a patch is available to prevent the execution of arbitrary code. Restrict access to the
help: URI handler to minimize the risk of exploitation. Avoid using the runscript parameter in the Safari web browser until the issue is resolved.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Macos X
Safari