漏洞标题
N/A
漏洞描述信息
在Mac OS X上的Apple Safari以及在Windows 3.1.2之前,不会提示用户下载具有未识别Content类型的对象,这允许远程攻击者将恶意软件放置在Windows上的(1)桌面目录或(2)Mac OS X上的Downloads目录中,随后允许远程攻击者利用Windows XP的Windows Internet Explorer 7或Windows XP、VISTA和Server 2003及2008中的SearchPath函数的未信任路径漏洞来在Windows上执行任意代码,这不同于CVE-2008-1032。注意:Apple仅考虑此漏洞为漏洞,因为Microsoft产品可以从桌面加载应用程序库,截至20080619,尚未为Mac OS X提供此问题的警告。
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
漏洞类别
N/A
漏洞标题
N/A
漏洞描述信息
Apple Safari on Mac OS X, and before 3.1.2 on Windows, does not prompt the user before downloading an object that has an unrecognized content type, which allows remote attackers to place malware into the (1) Desktop directory on Windows or (2) Downloads directory on Mac OS X, and subsequently allows remote attackers to execute arbitrary code on Windows by leveraging an untrusted search path vulnerability in (a) Internet Explorer 7 on Windows XP or (b) the SearchPath function in Windows XP, Vista, and Server 2003 and 2008, aka a "Carpet Bomb" and a "Blended Threat Elevation of Privilege Vulnerability," a different issue than CVE-2008-1032. NOTE: Apple considers this a vulnerability only because the Microsoft products can load application libraries from the desktop and, as of 20080619, has not covered the issue in an advisory for Mac OS X.
CVSS信息
N/A
漏洞类别
N/A
漏洞标题
Apple Safari权限许可和访问控制漏洞
漏洞描述信息
基于Mac OS X的Apple Safari以及基于Windows的3.1.2之前版本在下载带有无法识别内容类型的对象之前不能提示用户。远程攻击者可利用该漏洞在Windows桌面目录或Mac OS X下载目录中放置恶意软件,并且可利用Windows XP平台的Internet Explorer 7或者Windows XP,Vista,Server 2003以及2008的SearchPath函数中的不可信搜索路径漏洞执行任意代码。
CVSS信息
N/A
漏洞类别
授权问题