|
|
|
Vulnerability Note VU#356070Apple Terminal fails to properly sanitize input for "x-man-page" URIOverviewApple Terminal on Mac OS X fails to sanitize x-man-page URIs, allowing an attacker to execute arbitrary commands.I. DescriptionMac OS X 10.3 includes a URI handler called x-man-page. It causes Apple Terminal to display a man page by using a URI of this form: x-man-page://command. Applications such as Safari can link to x-man-page resources.Apple Terminal fails to sanitize input to the x-man-page URI handler. Escape characters embedded in the x-man-page URI could cause commands to be executed in the Terminal session.
Apple advises all users to apply Apple Security Update 2005-005, as it fixes this flaw and other critical security flaws.
References
Thanks to David Remahl for reporting this vulnerability. This document was written by Will Dormann.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||
|
||||||||||||||||||||||||||||||||||||