PT-2008-1713 · Apple · Safari+3
Published
2008-03-18
·
Updated
2017-08-08
·
CVE-2008-0052
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
CoreServices in Apple Mac OS X version 10.4.11
Description
The issue allows remote attackers to force Safari users into opening an .ief file in AppleWorks, even when the "Open 'Safe' files" preference is set, because CoreServices treats .ief as a safe file type.
Recommendations
For CoreServices in Apple Mac OS X version 10.4.11, consider changing the file type association for .ief files to prevent them from being opened in AppleWorks by default, as a temporary workaround until a patch is available.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Appleworks
Coreservices
Macos X
Safari