PT-2006-4379 · Apple · Macos X+2

Published

2006-08-03

·

Updated

2017-07-20

·

CVE-2006-3504

CVSS v2.0

5.1

Medium

VectorAV:N/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Apple Mac OS X version 10.4.7
Description The issue concerns the Download Validation in LaunchServices, which can incorrectly identify certain HTML as "safe". This could allow attackers to execute Javascript code in a local context when the "Open 'safe' files after downloading" option is enabled in Safari.
Recommendations For Apple Mac OS X version 10.4.7, consider disabling the "Open 'safe' files after downloading" option in Safari to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-3504

Affected Products

Launchservices
Macos X
Safari