CVE-2009-2808

Severity

54%

Complexity

55%

Confidentiality

106%

Per: http://support.apple.com/kb/HT3937 * Help Viewer CVE-ID: CVE-2009-2808 Available for: Mac OS X v10.5.8, Mac OS X Server v10.5.8, Mac OS X v10.6 and v10.6.1, Mac OS X Server v10.6 and v10.6.1 Impact: Using Help Viewer on an untrusted network may result in arbitrary code execution Description: Help Viewer does not use HTTPS for viewing remote Apple Help content. A user on the local network may send spoofed HTTP responses containing malicious help:runscript links. This update addresses the issue by using HTTPS when requesting remote Apple Help content. Credit to Brian Mastenbrook for reporting this issue.

Help Viewer in Apple Mac OS X before 10.6.2 does not use an HTTPS connection to retrieve Apple Help content from a web site, which allows man-in-the-middle attackers to send a crafted help:runscript link, and thereby execute arbitrary code, via a spoofed response.

Per: http://support.apple.com/kb/HT3937 * Help Viewer CVE-ID: CVE-2009-2808 Available for: Mac OS X v10.5.8, Mac OS X Server v10.5.8, Mac OS X v10.6 and v10.6.1, Mac OS X Server v10.6 and v10.6.1 Impact: Using Help Viewer on an untrusted network may result in arbitrary code execution Description: Help Viewer does not use HTTPS for viewing remote Apple Help content. A user on the local network may send spoofed HTTP responses containing malicious help:runscript links. This update addresses the issue by using HTTPS when requesting remote Apple Help content. Credit to Brian Mastenbrook for reporting this issue.

CVSS 2.0 Base Score 5.4. CVSS Attack Vector: adjacent_network. CVSS Attack Complexity: medium. CVSS Vector: (AV:A/AC:M/Au:N/C:P/I:P/A:P).

Overview

First reported 15 years ago

2009-11-10 19:30:00

Last updated 15 years ago

2009-11-17 07:02:00

Affected Software

Apple Mac OS X 10.0

10.0

Apple Mac OS X 10.0.0

10.0.0

Apple Mac OS X 10.0.1

10.0.1

Apple Mac OS X 10.0.2

10.0.2

Apple Mac OS X 10.0.3

10.0.3

Apple Mac OS X 10.0.4

10.0.4

Apple Mac OS X 10.1

10.1

Apple Mac OS X 10.1.0

10.1.0

Apple Mac OS X 10.1.1

10.1.1

Apple Mac OS X 10.1.2

10.1.2

Apple Mac OS X 10.1.3

10.1.3

Apple Mac OS X 10.1.4

10.1.4

Apple Mac OS X 10.1.5

10.1.5

Apple Mac OS X 10.2

10.2

Apple Mac OS X 10.2.0

10.2.0

Apple Mac OS X 10.2.1

10.2.1

Apple Mac OS X 10.2.2

10.2.2

Apple Mac OS X 10.2.3

10.2.3

Apple Mac OS X 10.2.4

10.2.4

Apple Mac OS X 10.2.5

10.2.5

Apple Mac OS X 10.2.6

10.2.6

Apple Mac OS X 10.2.7

10.2.7

Apple Mac OS X 10.2.8

10.2.8

Apple Mac OS X 10.3

10.3

Apple Mac OS X 10.3.0

10.3.0

Apple Mac OS X 10.3.1

10.3.1

Apple Mac OS X 10.3.2

10.3.2

Apple Mac OS X 10.3.3

10.3.3

Apple Mac OS X 10.3.4

10.3.4

Apple Mac OS X 10.3.5

10.3.5

Apple Mac OS X 10.3.6

10.3.6

Apple Mac OS X 10.3.7

10.3.7

Apple Mac OS X 10.3.8

10.3.8

Apple Mac OS X 10.3.9

10.3.9

Apple Mac OS X 10.4

10.4

Apple Mac OS X 10.4.0

10.4.0

Apple Mac OS X 10.4.1

10.4.1

Apple Mac OS X 10.4.2

10.4.2

Apple Mac OS X 10.4.3

10.4.3

Apple Mac OS X 10.4.4

10.4.4

Apple Mac OS X 10.4.5

10.4.5

Apple Mac OS X 10.4.6

10.4.6

Apple Mac OS X 10.4.7

10.4.7

Apple Mac OS X 10.4.8

10.4.8

Apple Mac OS X 10.4.9

10.4.9

Apple Mac OS X 10.4.10

10.4.10

Apple Mac OS X 10.4.11

10.4.11

Apple Mac OS X 10.5

10.5

Apple Mac OS X 10.5.0

10.5.0

Apple Mac OS X 10.5.1

10.5.1

Apple Mac OS X 10.5.2

10.5.2

Apple Mac OS X 10.5.3

10.5.3

Apple Mac OS X 10.5.4

10.5.4

Apple Mac OS X 10.5.5

10.5.5

Apple Mac OS X 10.5.6

10.5.6

Apple Mac OS X 10.5.7

10.5.7

Apple Mac OS X 10.5.8

10.5.8

Apple Mac OS X

Apple Mac OS X Server 10.0

10.0

Apple Mac OS X Server 10.0.0

10.0.0

Apple Mac OS X Server 10.0.1

10.0.1

Apple Mac OS X Server 10.0.2

10.0.2

Apple Mac OS X Server 10.0.3

10.0.3

Apple Mac OS X Server 10.0.4

10.0.4

Apple Mac OS X Server 10.1

10.1

Apple Mac OS X Server 10.1.0

10.1.0

Apple Mac OS X Server 10.1.1

10.1.1

Apple Mac OS X Server 10.1.2

10.1.2

Apple Mac OS X Server 10.1.3

10.1.3

Apple Mac OS X Server 10.1.4

10.1.4

Apple Mac OS X Server 10.1.5

10.1.5

Apple Mac OS X Server 10.2

10.2

Apple Mac OS X Server 10.2.0

10.2.0

Apple Mac OS X Server 10.2.1

10.2.1

Apple Mac OS X Server 10.2.2

10.2.2

Apple Mac OS X Server 10.2.3

10.2.3

Apple Mac OS X Server 10.2.4

10.2.4

Apple Mac OS X Server 10.2.5

10.2.5

Apple Mac OS X Server 10.2.6

10.2.6

Apple Mac OS X Server 10.2.7

10.2.7

Apple Mac OS X Server 10.2.8

10.2.8

Apple Mac OS X Server 10.3

10.3

Apple Mac OS X Server 10.3.0

10.3.0

Apple Mac OS X Server 10.3.1

10.3.1

Apple Mac OS X Server 10.3.2

10.3.2

Apple Mac OS X Server 10.3.3

10.3.3

Apple Mac OS X Server 10.3.4

10.3.4

Apple Mac OS X Server 10.3.5

10.3.5

Apple Mac OS X Server 10.3.6

10.3.6

Apple Mac OS X Server 10.3.7

10.3.7

Apple Mac OS X Server 10.3.8

10.3.8

Apple Mac OS X Server 10.3.9

10.3.9

Apple Mac OS X Server 10.4

10.4

Apple Mac OS X Server 10.4.0

10.4.0

Apple Mac OS X Server 10.4.1

10.4.1

Apple Mac OS X Server 10.4.2

10.4.2

Apple Mac OS X Server 10.4.3

10.4.3

Apple Mac OS X Server 10.4.4

10.4.4

Apple Mac OS X Server 10.4.5

10.4.5

Apple Mac OS X Server 10.4.6

10.4.6

Apple Mac OS X Server 10.4.7

10.4.7

Apple Mac OS X Server 10.4.8

10.4.8

Apple Mac OS X Server 10.4.9

10.4.9

Apple Mac OS X Server 10.4.10

10.4.10

Apple Mac OS X Server 10.4.11

10.4.11

Apple Mac OS X Server 10.5

10.5

Apple Mac OS X Server 10.5.0

10.5.0

Apple Mac OS X Server 10.5.1

10.5.1

Apple Mac OS X Server 10.5.2

10.5.2

Apple Mac OS X Server 10.5.3

10.5.3

Apple Mac OS X Server 10.5.4

10.5.4

Apple Mac OS X Server 10.5.5

10.5.5

Apple Mac OS X Server 10.5.6

10.5.6

Apple Mac OS X Server 10.5.7

10.5.7

Apple Mac OS X Server 10.5.8

10.5.8

Apple Mac OS X Server

Stay updated

ExploitPedia is constantly evolving. Sign up to receive a notification when we release additional functionality.

Get in touch

If you'd like to report a bug or have any suggestions for improvements then please do get in touch with us using this form. We will get back to you as soon as we can.