Mac OS X Security Vulnerabilities Rated "Extremely Critical" by Secunia

Here's Secunia's description of them:

Two vulnerabilities have been reported in Mac OS X, allowing malicious web sites to compromise a vulnerable system.

1) The problem is that the "help" URI handler allows execution of arbitrary local scripts (.scpt) via the classic directory traversal character sequence using "help:runscript".

2) It is reportedly also possible to silently place arbitrary files in a known location, including script files, on a user's system using the "disk" URI handler.

Various variants of the URI handler vulnerabilities are currently being discussed.

This has been confirmed on Macintosh OS X using Safari 1.2.1 (v125.1) and Internet Explorer 5.2. Other browsers may also be used as attack vectors.

Apple is looking into them according to MacCentral. [Dana Baggett]

Saw something? Send a tip

The archive ran on reader tips. What did you see, where, and do you want the credit?

Read by the editor. Never published without your say.

More in Mac OS · This month in the archive