| CVE-ID |
CVE-2008-2540
(under review)
|
• Severity Rating • Fix Information • Vulnerable Software Versions • SCAP Mappings
|
| Description |
| Apple Safari on Mac OS X, and before 3.1.2 on Windows, does not prompt
the user before downloading an object that has an unrecognized content
type, which allows remote attackers to place malware into the (1)
Desktop directory on Windows or (2) Downloads directory on Mac OS X,
aka a "Carpet Bomb," a different issue than CVE-2008-1032. NOTE: Apple
considers this a vulnerability only because of certain behavior of the
Windows desktop and, as of 20080619, has not covered the issue in an
advisory for Mac OS X. NOTE: Microsoft describes the issue on the
Windows platform as "a blended threat that allows remote code
execution."
|
| References |
|
Note: References are provided for the convenience of the reader to help distinguish between vulnerabilities. The list is not intended to be complete.
|
|
|
| Status |
| Candidate |
This CVE Identifier has "Candidate" status and must be reviewed and accepted by the CVE Editorial Board before it can be updated to official "Entry" status on the CVE List. It may be modified or even rejected in the future. |
| Phase |
| Assigned (20080603) |
| Votes |
|
| Comments |
|
| Candidate assigned on 20080603 and proposed on N/A |
|
|
|
For More Information: cve@mitre.org
|