CVE-2004-0485

medium

Description

The default protocol helper for the disk: URI on Mac OS X 10.3.3 and 10.2.8 allows remote attackers to write arbitrary files by causing a disk image file (.dmg) to be mounted as a disk volume.

References

http://fundisom.com/owned/warning

http://lists.apple.com/mhonarc/security-announce/msg00053.html

http://lists.seifried.org/pipermail/security/2004-May/003743.html

http://secunia.com/advisories/11622/

http://www.kb.cert.org/vuls/id/210606

https://exchange.xforce.ibmcloud.com/vulnerabilities/16166

Details

Source: MITRE

Published: 2004-07-07

Updated: 2017-07-11

Risk Information

CVSS v2

Base Score: 5

Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Impact Score: 2.9

Exploitability Score: 10

Severity: MEDIUM