OS X alert: Help Viewer/browser security vulnerability

P
Posted By
Phosphor
May 19, 2004
Views
862
Replies
0
Status
Closed
Go take care of this. If you find the "More Internet" preference pane disk image slow to D/L, go to the alternate mirror site and get it. Follow the instructions on the page linked below.

(via MacFixit and other sources…)

<http://www.macfixit.com/article.php?story=20040519024257161>

"We previously reported a potential vulnerability in OS X relating to browsers’ use of the help URL protocol. Although this was originally reported by many sources as a Safari vulnerability, it’s actually exploitable through any browser that properly supports URLs that include the "help" protocol (e.g., a URL that begins with <http://)> — which should be any browser that fully supports OS X’s default application helper settings. In fact, through the use of meta "refresh" tags in the source of a Web page, the vulnerability can be exploited without a user even clicking on a "malicious" link."

"In addition, although the original reports around the Web noted the use of Safari’s ability to auto-mount disk images — followed by a help URL that uses Help Viewer’s ability to execute AppleScripts, in order to run a malicious script located on the mounted disk image — this is only one way in which a help URL could be used to cause damage to a user’s data."

MacBook Pro 16” Mockups 🔥

– in 4 materials (clay versions included)

– 12 scenes

– 48 MacBook Pro 16″ mockups

– 6000 x 4500 px

Related Discussion Topics

Nice and short text about related topics in discussion sections