|
|

CVE Reference: CVE-2008-2540 |
|
| NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE. | |
|
Original Page at CVE MITRE: CVE-2008-2540 |
|
|
Description: Apple Safari on Mac OS X, and before 3.1.2 on Windows, does not prompt the user before downloading an object that has an unrecognized content type, which allows remote attackers to place malware into the (1) Desktop directory on Windows or (2) Downloads directory on Mac OS X, and subsequently allows remote attackers to execute arbitrary code on Windows by leveraging an untrusted search path vulnerability in (a) Internet Explorer 7 on Windows XP or (b) the SearchPath function in Windows XP, Vista, and Server 2003 and 2008, aka a "Carpet Bomb" and a "Blended Threat Elevation of Privilege Vulnerability," a different issue than CVE-2008-1032. NOTE: Apple considers this a vulnerability only because the Microsoft products can load application libraries from the desktop and, as of 20080619, has not covered the issue in an advisory for Mac OS X. |
|
|
CVE Status: Candidate |
|
|
References: XF http://xforce.iss.net/xforce/xfdb/42765 ST 1022047 1020150 SAID Secunia Advisory: SA30467 OVAL http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:8509 http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6108 http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5782 MS http://www.microsoft.com/technet/security/bulletin/ms09-015.mspx http://www.microsoft.com/technet/security/Bulletin/MS09-014.mspx MISC http://www.microsoft.com/technet/security/advisory/953818.mspx http://blogs.zdnet.com/security/?p=1230 http://www.dhanjani.com/archives/2008/05/safari_carpet_bomb.html http://aviv.raffon.net/2008/05/31/SafariPwnsInternetExplorer.aspx CONFIRM http://support.avaya.com/elmodocs2/security/ASA-2009-133.htm http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=871138 CERT http://www.us-cert.gov/cas/techalerts/TA09-104A.html BID 29445 APPLE http://lists.apple.com/archives/security-announce/2008//Jun/msg00001.html |
|
| Return to the previous page. |
Not a customer already?Learn more about how our market leading Vulnerability Management solutions can help you manage risk and ensure compliance. |