CVE-2008-1032
published 2008-06-02CVE-2008-1032: Incomplete blacklist vulnerability in CoreTypes in Apple Mac OS X before 10.5.3 allows user-assisted remote attackers to execute arbitrary code via an (1)…
medium6.8CVSS 3.1
AVNACMAuNCPIPAP
Incomplete blacklist vulnerability in CoreTypes in Apple Mac OS X before 10.5.3 allows user-assisted remote attackers to execute arbitrary code via an (1) Automator, (2) Help, (3) Safari, or (4) Terminal content type for a downloadable object, which does not trigger a "potentially unsafe" warning message in (a) the Download Validation feature in Mac OS X 10.4 or (b) the Quarantine feature in Mac OS X 10.5.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | safari | < 3.1.2 | 3.1.2 |
GHSA
GHSA-6mfp-r743-cc3p: Apple Safari on Mac OS X, and before 3
ghsa_unreviewed·2022-05-01·CVSS 6.8
CVE-2008-2540 [MEDIUM] GHSA-6mfp-r743-cc3p: Apple Safari on Mac OS X, and before 3
Apple Safari on Mac OS X, and before 3.1.2 on Windows, does not prompt the user before downloading an object that has an unrecognized content type, which allows remote attackers to place malware into the (1) Desktop directory on Windows or (2) Downloads directory on Mac OS X, and subsequently allows remote attackers to execute arbitrary code on Windows by leveraging an untrusted search path vulnerability in (a) Internet Explorer 7 on Windows XP or (b) the SearchPath function in Windows XP, Vista, and Server 2003 and 2008, aka a "Carpet Bomb" and a "Blended Threat Elevation of Privilege Vulnerability," a different issue than CVE-2008-1032. NOTE: Apple considers this a vulnerability only because the Microsoft products can load application libraries from the desktop and, as of 20080619, has n
GHSA
GHSA-m7wx-wjm6-293j: Incomplete blacklist vulnerability in CoreTypes in Apple Mac OS X before 10
ghsa_unreviewed·2022-05-01
CVE-2008-1032 [MEDIUM] GHSA-m7wx-wjm6-293j: Incomplete blacklist vulnerability in CoreTypes in Apple Mac OS X before 10
Incomplete blacklist vulnerability in CoreTypes in Apple Mac OS X before 10.5.3 allows user-assisted remote attackers to execute arbitrary code via an (1) Automator, (2) Help, (3) Safari, or (4) Terminal content type for a downloadable object, which does not trigger a "potentially unsafe" warning message in (a) the Download Validation feature in Mac OS X 10.4 or (b) the Quarantine feature in Mac OS X 10.5.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lists.apple.com/archives/security-announce/2008//May/msg00001.htmlhttp://secunia.com/advisories/30430http://securitytracker.com/id?1020137http://www.securityfocus.com/bid/29412http://www.securityfocus.com/bid/29481http://www.us-cert.gov/cas/techalerts/TA08-150A.htmlhttp://www.vupen.com/english/advisories/2008/1697https://exchange.xforce.ibmcloud.com/vulnerabilities/42711http://lists.apple.com/archives/security-announce/2008//May/msg00001.htmlhttp://secunia.com/advisories/30430http://securitytracker.com/id?1020137http://www.securityfocus.com/bid/29412http://www.securityfocus.com/bid/29481http://www.us-cert.gov/cas/techalerts/TA08-150A.htmlhttp://www.vupen.com/english/advisories/2008/1697https://exchange.xforce.ibmcloud.com/vulnerabilities/42711
2008-06-02
Published