Location via proxy:   [ UP ]  
[Report a bug]   [Manage cookies]                
Your Ad Here Your Ad Here

 
CVE-ID

CVE-2008-2540

(under review)
• Severity Rating • Fix Information • Vulnerable Software Versions • SCAP Mappings
Description
Apple Safari on Mac OS X, and before 3.1.2 on Windows, does not prompt the user before downloading an object that has an unrecognized content type, which allows remote attackers to place malware into the (1) Desktop directory on Windows or (2) Downloads directory on Mac OS X, aka a "Carpet Bomb," a different issue than CVE-2008-1032. NOTE: Apple considers this a vulnerability only because of certain behavior of the Windows desktop and, as of 20080619, has not covered the issue in an advisory for Mac OS X. NOTE: Microsoft describes the issue on the Windows platform as "a blended threat that allows remote code execution."
References
Note: References are provided for the convenience of the reader to help distinguish between vulnerabilities. The list is not intended to be complete.
Status
Candidate This CVE Identifier has "Candidate" status and must be reviewed and accepted by the CVE Editorial Board before it can be updated to official "Entry" status on the CVE List. It may be modified or even rejected in the future.
Phase
Assigned (20080603)
Votes
Comments
Candidate assigned on 20080603 and proposed on N/A
 
Your Ad Here Sedo - Buy and Sell Domain Names and Websites project info: pokeproxy.com Statistics for project pokeproxy.com etracker® web controlling instead of log file analysis