PT-2006-2465 · Apple · Safari+1
Published
2006-05-12
·
Updated
2017-07-20
·
CVE-2006-1457
CVSS v2.0
2.6
Low
| Vector | AV:N/AC:H/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Safari on Apple Mac OS X version 10.4.6
Description
The issue allows remote attackers to potentially overwrite arbitrary files on the system. This is possible when the "Open `safe' files after downloading" option is enabled, and Safari automatically expands archives. If an archive contains a symlink, it could be used to overwrite files.
Recommendations
For Safari on Apple Mac OS X version 10.4.6, consider disabling the "Open `safe' files after downloading" option to prevent automatic expansion of archives and minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Macos X
Safari