Collected research
Launch any file path from web page
CVE-2011-3230 - Launch any file path from web page
A web page could hand any file: URL to Mac OS X LaunchServices through document.location, which then runs the binary, opens the application, or opens the file in its default handler. Only the quarantine bit stops a freshly downloaded binary, so anything already on disk launches. Apple fixed it in HT5000 as CVE-2011-3230.
Record
- Document
- CVE-2011-3230 - Launch any file path from web page
- Researcher
- Aaron Sigel
- Published by
- vttynotes.blogspot.com
- Format
- Advisory
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Aaron Sigel, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .