Brief Hands-On Report--Apple Updated iWork, Pages to 1.0.2 and Keynote to 2.0.2
CVE-ID: CAN-2005-1408
Available for: Keynote 2, Keynote 2.0.1
Impact: A maliciously modified Keynote presentation could be constructed to retrieve files from the local system.
Description: With a specially crafted Keynote presentation and the use of the "keynote:" URI handler, it is possible that local files could be read and then sent to an arbitrary network location. This issue has been addressed in two ways: References to external resources have been limited, and the registration of the "keynote:" URI handler has been removed. This issue does not affect Keynote versions prior to Keynote 2. Credit to David Remahl (www.remahl.se/david) for reporting this issue.
We updated our copies of Pages and Keynote 2 with no problems. We weren't having any problems with the previous versions during our use and none have cropped up since updating. [Biill Fox]
Saw something? Send a tip
The archive ran on reader tips. What did you see, where, and do you want the credit?