Apple Mac OS X Help Viewer 'help://' URI Cross Site Scripting Vulnerability
BID:40886
Info
Apple Mac OS X Help Viewer 'help://' URI Cross Site Scripting Vulnerability
| Bugtraq ID: | 40886 |
| Class: | Input Validation Error |
| CVE: |
CVE-2010-1373 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 15 2010 12:00AM |
| Updated: | Jun 15 2010 12:00AM |
| Credit: | Clint Ruoho of Laconic Security |
| Vulnerable: |
Apple Mac OS X Server 10.6.3 Apple Mac OS X Server 10.6.2 Apple Mac OS X Server 10.6.1 Apple Mac OS X Server 10.6 Apple Mac OS X 10.6.3 Apple Mac OS X 10.6.2 Apple Mac OS X 10.6.1 Apple Mac OS X 10.6 |
| Not Vulnerable: |
Apple Mac OS X Server 10.6.4 Apple Mac OS X 10.6.4 |
Discussion
Apple Mac OS X Help Viewer 'help://' URI Cross Site Scripting Vulnerability
Apple Mac OS X Help Viewer is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks.
NOTE: This issue was previously covered in BID 40871 (Apple Mac OS X Prior to 10.6.4 Multiple Security Vulnerabilities), but has been given its own record to better document it.
Apple Mac OS X Help Viewer is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks.
NOTE: This issue was previously covered in BID 40871 (Apple Mac OS X Prior to 10.6.4 Multiple Security Vulnerabilities), but has been given its own record to better document it.
Exploit / POC
Apple Mac OS X Help Viewer 'help://' URI Cross Site Scripting Vulnerability
Attackers can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
Attackers can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
Solution / Fix
Apple Mac OS X Help Viewer 'help://' URI Cross Site Scripting Vulnerability
Solution:
Updates are available. Please see the references for details.
Apple Mac OS X 10.6
Apple Mac OS X Server 10.6
Apple Mac OS X Server 10.6.1
Apple Mac OS X 10.6.1
Apple Mac OS X 10.6.2
Apple Mac OS X Server 10.6.2
Apple Mac OS X Server 10.6.3
Apple Mac OS X 10.6.3
Solution:
Updates are available. Please see the references for details.
Apple Mac OS X 10.6
-
Apple MacOSXUpdCombo10.6.4.dmg
http://www.apple.com/support/downloads/
Apple Mac OS X Server 10.6
-
Apple MacOSXServUpdCombo10.6.4.dmg
http://www.apple.com/support/downloads/
Apple Mac OS X Server 10.6.1
-
Apple MacOSXServUpdCombo10.6.4.dmg
http://www.apple.com/support/downloads/
Apple Mac OS X 10.6.1
-
Apple MacOSXUpdCombo10.6.4.dmg
http://www.apple.com/support/downloads/
Apple Mac OS X 10.6.2
-
Apple MacOSXUpdCombo10.6.4.dmg
http://www.apple.com/support/downloads/
Apple Mac OS X Server 10.6.2
-
Apple MacOSXServUpdCombo10.6.4.dmg
http://www.apple.com/support/downloads/
Apple Mac OS X Server 10.6.3
-
Apple MacOSXServerUpd10.6.4.dmg
http://www.apple.com/support/downloads/
Apple Mac OS X 10.6.3
-
Apple MacOSXUpd10.6.4.dmg
http://www.apple.com/support/downloads/
References
Apple Mac OS X Help Viewer 'help://' URI Cross Site Scripting Vulnerability
References:
References:
- Mac OS X Homepage (Apple)