CoreServices in Apple Mac OS X 10.4.11 treats .ief as a safe file type, which allows remote attackers to force Safari users into opening an .ief file in AppleWorks, even when the "Open 'Safe' files" preference is set.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/28304 | vdb entry |
http://www.us-cert.gov/cas/techalerts/TA08-079A.html | third party advisory us government resource |
http://www.vupen.com/english/advisories/2008/0924/references | vdb entry |
http://secunia.com/advisories/29420 | third party advisory |
http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html | patch vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/41312 | vdb entry |
http://www.securityfocus.com/bid/28384 | vdb entry |
http://docs.info.apple.com/article.html?artnum=307562 | |
http://www.securitytracker.com/id?1019671 | vdb entry |