Apple iChat Remote Link Application Execution Vulnerability
BID:11207
Info
Apple iChat Remote Link Application Execution Vulnerability
| Bugtraq ID: | 11207 |
| Class: | Design Error |
| CVE: |
CVE-2004-0873 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 17 2004 12:00AM |
| Updated: | Jul 12 2009 07:06AM |
| Credit: | Discovery of this issue is credited to <[email protected]>. |
| Vulnerable: |
Apple iChat AV 2.1 Apple iChat AV 2.0 Apple iChat 1.0.1 |
| Not Vulnerable: | |
Discussion
Apple iChat Remote Link Application Execution Vulnerability
Reportedly Apple iChat is vulnerable to a remote link application execution vulnerability. This issue is due to a design error that allows attacker to execute arbitrary commands through a vulnerable application.
An attacker can leverage this issue to execute arbitrary application on an unsuspecting user's computer. The impact of this issue may be increased when an attacker entices a victim to first download an application or has another means of placing an application on the victim's computer, and then exploits this issue to execute it.
Reportedly Apple iChat is vulnerable to a remote link application execution vulnerability. This issue is due to a design error that allows attacker to execute arbitrary commands through a vulnerable application.
An attacker can leverage this issue to execute arbitrary application on an unsuspecting user's computer. The impact of this issue may be increased when an attacker entices a victim to first download an application or has another means of placing an application on the victim's computer, and then exploits this issue to execute it.
Exploit / POC
Apple iChat Remote Link Application Execution Vulnerability
No exploit is required to leverage this issue.
No exploit is required to leverage this issue.
Solution / Fix
Apple iChat Remote Link Application Execution Vulnerability
Solution:
Apple has released Security Update 2004-09-16 dealing with this issue. Please see the referenced advisory for more information.
Apple iChat 1.0.1
Apple iChat AV 2.0
Apple iChat AV 2.1
Solution:
Apple has released Security Update 2004-09-16 dealing with this issue. Please see the referenced advisory for more information.
Apple iChat 1.0.1
-
Apple SecUpd2004-09-16Jag.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=04757&plat form=osx&method=sa/SecUpd2004-09-16Jag.dmg
Apple iChat AV 2.0
-
Apple SecUpd2004-09-16JagAV.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=04756&plat form=osx&method=sa/SecUpd2004-09-16JagAV.dmg
Apple iChat AV 2.1
-
Apple SecUpd2004-09-16Pan.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty1.pl/product=04758&plat form=osx&method=sa/SecUpd2004-09-16Pan.dmg
References
Apple iChat Remote Link Application Execution Vulnerability
References:
References:
- iChat Home Page (Apple)
- Mac OS X Homepage (Apple)