PT-2005-2334 · Apple · Applescript Editor+1

David Remahl

·

Published

2005-05-04

·

Updated

2011-03-08

·

CVE-2005-1331

CVSS v2.0

5.1

Medium

VectorAV:N/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Mac OS X version 10.3.9
Description: The issue concerns the AppleScript Editor in Mac OS X, which fails to properly display script code for an applescript: URI. This can lead to a discrepancy between the displayed code and the actual code that would be executed, potentially allowing remote attackers to deceive users into running malicious code. This can be achieved through the use of certain URI characters, including NULL, control characters, and homographs.
Recommendations: For Mac OS X version 10.3.9, consider avoiding the use of the AppleScript Editor for executing scripts from untrusted sources until a fix is available. As a temporary workaround, restrict the handling of applescript: URIs to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-1331

Affected Products

Applescript Editor
Macos X