Dashboard in Apple Mac OS X Tiger 10.4 allows attackers to execute arbitrary commands by overriding the behavior of system widgets via a user widget with the same bundle identifier (CFBundleIdentifier), a different vulnerability than CVE-2005-1474.
Link | Tags |
---|---|
http://www.kb.cert.org/vuls/id/983429 | third party advisory us government resource |
http://www1.cs.columbia.edu/~aaron/files/widgets/ | vendor advisory exploit |