PT-2005-2339 · Apple · Help Viewer+1
David Remahl
·
Published
2005-05-04
·
Updated
2008-09-05
·
CVE-2005-1337
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Apple Help Viewer versions 2.0.7 and 3.0.0 in Mac OS X 10.3.9
Description:
The issue allows remote attackers to read and execute arbitrary scripts with less restrictive privileges via a help:// URI.
Recommendations:
For Apple Help Viewer version 2.0.7, consider disabling the handling of help:// URIs until a patch is available.
For Apple Help Viewer version 3.0.0, restrict access to the help:// URI scheme to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Help Viewer
Macos X