Apple Mac OS X Help Viewer HTML Document Remote Code Execution Vulnerability

Apple Mac OS X is prone to a remote code-execution vulnerability.

An attacker can exploit this issue by enticing an unsuspecting victim to open a malicious 'help:' URI.

A successful exploit will allow the attacker to execute arbitrary AppleScript code. This may lead to the execution of arbitrary code or aid in further attacks.

NOTE: This issue was previously covered in BID 34926 (Apple Mac OS X 2009-002 Multiple Security Vulnerabilities), but has been assigned its own record to better document it.


 

Privacy Statement
Copyright 2010, SecurityFocus