Apple Keynote Local File Disclosure Vulnerability
BID:13771
Info
Apple Keynote Local File Disclosure Vulnerability
| Bugtraq ID: | 13771 |
| Class: | Design Error |
| CVE: |
CVE-2005-1408 |
| Remote: | Yes |
| Local: | No |
| Published: | May 25 2005 12:00AM |
| Updated: | Jul 12 2009 02:56PM |
| Credit: | Discovery is credited to David Remahl. |
| Vulnerable: |
Apple Keynote 2.0.1 Apple Keynote 2.0 |
| Not Vulnerable: |
Apple Keynote 2.0.2 |
Discussion
Apple Keynote Local File Disclosure Vulnerability
Apple Keynote is prone to a vulnerability that may allow attackers to retrieve the contents of files on the affected computer.
This could be exploited through use of the 'keynote:' URI protocol handler in combination with a malicious Keynote presentation.
Apple Keynote is prone to a vulnerability that may allow attackers to retrieve the contents of files on the affected computer.
This could be exploited through use of the 'keynote:' URI protocol handler in combination with a malicious Keynote presentation.
Exploit / POC
Apple Keynote Local File Disclosure Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Apple Keynote Local File Disclosure Vulnerability
Solution:
Apple has released Keynote 2.0.2 to address this issue.
Apple Keynote 2.0
Apple Keynote 2.0.1
Solution:
Apple has released Keynote 2.0.2 to address this issue.
Apple Keynote 2.0
-
Apple Keynote 2.0.2
http://www.apple.com/iwork/keynote/download/
Apple Keynote 2.0.1
-
Apple Keynote 2.0.2
http://www.apple.com/iwork/keynote/download/
References
Apple Keynote Local File Disclosure Vulnerability
References:
References: