CVE Database
/

CVE-2008-2540

Back to search

CVE-2008-2540

Published: Jun 3, 2008

Modified: Aug 7, 2024

PUBLISHED

Description

Apple Safari on Mac OS X, and before 3.1.2 on Windows, does not prompt the user before downloading an object that has an unrecognized content type, which allows remote attackers to place malware into the (1) Desktop directory on Windows or (2) Downloads directory on Mac OS X, and subsequently allows remote attackers to execute arbitrary code on Windows by leveraging an untrusted search path vulnerability in (a) Internet Explorer 7 on Windows XP or (b) the SearchPath function in Windows XP, Vista, and Server 2003 and 2008, aka a "Carpet Bomb" and a "Blended Threat Elevation of Privilege Vulnerability," a different issue than CVE-2008-1032. NOTE: Apple considers this a vulnerability only because the Microsoft products can load application libraries from the desktop and, as of 20080619, has not covered the issue in an advisory for Mac OS X.

VendorProductVersions

n/a

n/a

affected
n/a

References

30467
third-party-advisory
x_refsource_SECUNIA
ADV-2009-1028
vdb-entry
x_refsource_VUPEN
1022047
vdb-entry
x_refsource_SECTRACK
1020150
vdb-entry
x_refsource_SECTRACK
29445
vdb-entry
x_refsource_BID
ADV-2009-1029
vdb-entry
x_refsource_VUPEN
TA09-104A
third-party-advisory
x_refsource_CERT
oval:org.mitre.oval:def:8509
vdb-entry
signature
x_refsource_OVAL
MS09-014
vendor-advisory
x_refsource_MS
APPLE-SA-2008-06-19
vendor-advisory
x_refsource_APPLE
oval:org.mitre.oval:def:5782
vdb-entry
signature
x_refsource_OVAL
MS09-015
vendor-advisory
x_refsource_MS
oval:org.mitre.oval:def:6108
vdb-entry
signature
x_refsource_OVAL
ADV-2008-1706
vdb-entry
x_refsource_VUPEN

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now