CVE-2008-4234
Incomplete blacklist vulnerability in the Quarantine feature in CoreTypes in Apple Mac OS X 10.5 before 10.5.6 allows user-assisted remote attackers to execute arbitrary code via an executable file with the content type indicating no application…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.55%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Incomplete blacklist vulnerability in the Quarantine feature in CoreTypes in Apple Mac OS X 10.5 before 10.5.6 allows user-assisted remote attackers to execute arbitrary code via an executable file with the content type indicating no application association for the file, which does not trigger a "potentially unsafe" warning message.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 4.55% probability · 91th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- apple/mac os x · apple/mac os x server
- Source
- cve@mitre.org
References
- http://lists.apple.com/archives/security-announce//2008//Dec/msg00000.htmlVendor Advisory
- http://secunia.com/advisories/33179Vendor Advisory
- http://support.apple.com/kb/HT3338Vendor Advisory
- http://www.securityfocus.com/bid/32839
- http://www.securitytracker.com/id?1021400
- http://www.us-cert.gov/cas/techalerts/TA08-350A.htmlUS Government Resource
- http://www.vupen.com/english/advisories/2008/3444
- https://exchange.xforce.ibmcloud.com/vulnerabilities/47689
- http://lists.apple.com/archives/security-announce//2008//Dec/msg00000.htmlVendor Advisory
- http://secunia.com/advisories/33179Vendor Advisory
- http://support.apple.com/kb/HT3338Vendor Advisory
- http://www.securityfocus.com/bid/32839
- http://www.securitytracker.com/id?1021400
- http://www.us-cert.gov/cas/techalerts/TA08-350A.htmlUS Government Resource
- http://www.vupen.com/english/advisories/2008/3444
- https://exchange.xforce.ibmcloud.com/vulnerabilities/47689
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.