PT-2005-2334 · Apple · Applescript Editor+1
David Remahl
·
Published
2005-05-04
·
Updated
2011-03-08
·
CVE-2005-1331
CVSS v2.0
5.1
Medium
| Vector | AV:N/AC:H/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Mac OS X version 10.3.9
Description:
The issue concerns the AppleScript Editor in Mac OS X, which fails to properly display script code for an applescript: URI. This can lead to a discrepancy between the displayed code and the actual code that would be executed, potentially allowing remote attackers to deceive users into running malicious code. This can be achieved through the use of certain URI characters, including NULL, control characters, and homographs.
Recommendations:
For Mac OS X version 10.3.9, consider avoiding the use of the AppleScript Editor for executing scripts from untrusted sources until a fix is available. As a temporary workaround, restrict the handling of applescript: URIs to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Applescript Editor
Macos X