OS X alert: Help Viewer/browser security vulnerability

P
Posted By
Phosphor
May 19, 2004
Views
862
Replies
0
Status
Closed
Go take care of this. If you find the "More Internet" preference pane disk image slow to D/L, go to the alternate mirror site and get it. Follow the instructions on the page linked below.

(via MacFixit and other sources…)

<http://www.macfixit.com/article.php?story=20040519024257161>

"We previously reported a potential vulnerability in OS X relating to browsers’ use of the help URL protocol. Although this was originally reported by many sources as a Safari vulnerability, it’s actually exploitable through any browser that properly supports URLs that include the "help" protocol (e.g., a URL that begins with <http://)> — which should be any browser that fully supports OS X’s default application helper settings. In fact, through the use of meta "refresh" tags in the source of a Web page, the vulnerability can be exploited without a user even clicking on a "malicious" link."

"In addition, although the original reports around the Web noted the use of Safari’s ability to auto-mount disk images — followed by a help URL that uses Help Viewer’s ability to execute AppleScripts, in order to run a malicious script located on the mounted disk image — this is only one way in which a help URL could be used to cause damage to a user’s data."

How to Improve Photoshop Performance

Learn how to optimize Photoshop for maximum speed, troubleshoot common issues, and keep your projects organized so that you can work faster than ever before!

Related Discussion Topics

Nice and short text about related topics in discussion sections