View this article at: http://www.macnn.com/articles/04/05/24/uri.exploit.in.os.x/
Monday, May 24, 2004 7:35am
Mac OS X: still vulnerable to URI exploit after patch
Secunia confirms that Apple's recent security update does not resolve the security issues related to the previously outlined URI Handler Registration Code Execution Vulnerability, which it continues to describe as "extremely critical." Secunia says "this problem is escalated due to the fact that it by default is possible to silently download and mount disk images using two known methods (silent download and execution of "safe" files and the "disk" URI). Furthermore, it is reportedly also possible to mount volumes using other methods such as SMB, AFS, FTP, DAV and others."