PT-2006-4379 · Apple · Macos X+2
Published
2006-08-03
·
Updated
2017-07-20
·
CVE-2006-3504
CVSS v2.0
5.1
Medium
| Vector | AV:N/AC:H/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Apple Mac OS X version 10.4.7
Description
The issue concerns the Download Validation in LaunchServices, which can incorrectly identify certain HTML as "safe". This could allow attackers to execute Javascript code in a local context when the "Open 'safe' files after downloading" option is enabled in Safari.
Recommendations
For Apple Mac OS X version 10.4.7, consider disabling the "Open 'safe' files after downloading" option in Safari to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Launchservices
Macos X
Safari