PT-2005-2696 · Apple · Macos X
Published
2005-06-08
·
Updated
2008-09-05
·
CVE-2005-1723
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Mac OS X versions 10.4.x up to 10.4.1
Description
The issue concerns a problem where LaunchServices in Mac OS X does not correctly identify certain file extensions and MIME types as unsafe. This occurs when an Apple Uniform Type Identifier (UTI) is not created upon adding a type to the database of unsafe types, potentially allowing attackers to bypass intended restrictions.
Recommendations
For Mac OS X versions 10.4.x up to 10.4.1, update to a version that properly handles the creation of Apple Uniform Type Identifiers (UTIs) for unsafe file types to prevent bypassing of restrictions.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Macos X