PT-2005-2696 · Apple · Macos X

Published

2005-06-08

·

Updated

2008-09-05

·

CVE-2005-1723

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Mac OS X versions 10.4.x up to 10.4.1
Description The issue concerns a problem where LaunchServices in Mac OS X does not correctly identify certain file extensions and MIME types as unsafe. This occurs when an Apple Uniform Type Identifier (UTI) is not created upon adding a type to the database of unsafe types, potentially allowing attackers to bypass intended restrictions.
Recommendations For Mac OS X versions 10.4.x up to 10.4.1, update to a version that properly handles the creation of Apple Uniform Type Identifiers (UTIs) for unsafe file types to prevent bypassing of restrictions.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-1723

Affected Products

Macos X