Description
LaunchServices in Apple Mac OS X 10.4.x up to 10.4.1 does not properly mark file extensions and MIME types as unsafe if an Apple Uniform Type Identifier (UTI) is not created when the type is added to the database of unsafe types, which could allow attackers to bypass intended restrictions.
References (2)
Core 2
Core References
Patch, Vendor Advisory vendor-advisory
x_refsource_apple
http://lists.apple.com/archives/security-announce/2005/Jun/msg00000.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://securitytracker.com/id?1014141
Scores
EPSS
0.0109
EPSS Percentile
62.1%
Details
Status
published
Products (2)
apple/mac_os_x_server
10.4
apple/mac_os_x_server
10.4.1
Published
Jun 08, 2005
Tracked Since
Feb 18, 2026