Apple Safari before 3.1.2 on Windows does not properly interpret the URLACTION_SHELL_EXECUTE_HIGHRISK Internet Explorer zone setting, which allows remote attackers to bypass intended access restrictions, and force a client system to download and execute arbitrary files.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.kb.cert.org/vuls/id/127185 | third party advisory us government resource |
http://secunia.com/advisories/30775 | third party advisory |
http://www.securitytracker.com/id?1020329 | vdb entry |
http://www.vupen.com/english/advisories/2008/1882/references | vdb entry |
http://www.securityfocus.com/bid/29835 | vdb entry |
http://lists.apple.com/archives/security-announce/2008//Jun/msg00001.html | patch vendor advisory |