Vulnerability Note VU#566875
Apple Help Viewer vulnerable to buffer overflow
A vulnerability in the way Apple Help Viewer handles specially crafted URLs may allow an attacker to execute arbitrary code or cause a denial of service.
According to Apple Security Update 2008-003:
An integer underflow in Help Viewer's handling of help:topic URLs may result in a buffer overflow. Accessing a malicious help:topic URL may lead to an unexpected application termination or arbitrary code execution.
Note that this issue affects systems running Mac OS X prior to version 10.5.
A remote, unauthenticated attacker may be able to execute arbitrary code or cause a denial of service.
Systems Affected (Learn More)
|Vendor||Status||Date Notified||Date Updated|
|Apple Computer, Inc.||Affected||-||29 May 2008|
CVSS Metrics (Learn More)
This issue was reported in Apple Security Update 2008-003. Apple credits Paul Haddad of PTH with reporting this issue.
This document was written by Chris Taschner.
- CVE IDs: CVE-2008-1034
- Date Public: 28 May 2008
- Date First Published: 29 May 2008
- Date Last Updated: 29 May 2008
- Severity Metric: 8.68
- Document Revision: 6
If you have feedback, comments, or additional information about this vulnerability, please send us email.