stargeek
PHP news website logo.
home    PHP scripts    articles    seo tools    links    search    contact    shop    realtors


Potential Safari/HelpViewer security vulnerability; AppleScript fix







Potential Safari/HelpViewer security
vulnerability; AppleScript fix

Potential Safari/HelpViewer security
vulnerability; AppleScript fix
05/17/2004 08:53 PM

The problem arises when this automatic opening behavior is combined with Apple HelpViewer's ability to automatically run programs via the "help:" protocol. A maliciously intended help file could therefore locate and launch a threatening file from within the mounted disk image.




This is a GrokNews Entry: (what is grok?)





Similar Items

Potential Safari/HelpViewer security vulnerability; AppleScript fix

Grok Headline matches for Potential Safari/HelpViewer security vulnerability; AppleScript fix

Mac OS X security update fixes Safari
vulnerability


Mac OS X security update fixes Safari
vulnerability
03/22/2005 05:04 PM
Apple on Monday issued a security update for Mac OS X that fixes several issues with the operating system, including a vulnerability in the company's Web browser, Safari. The update also addresses several other problems with the Mac OS X and Mac OS X Server.

Security Update 2004-05-24 Fixes
HelpViewer


Security Update 2004-05-24 Fixes
HelpViewer
05/21/2004 06:45 PM

An AppleScript to toggle JavaScript in
Safari


An AppleScript to toggle JavaScript in
Safari
05/20/2004 11:45 AM
Being a satisfied Safari user, I've never seen the need to disable JavaScript in my regular browsing; but this morning I came across a need to test several sites with JavaScript both enabled and disabled. Imagine my surprise ...

10.3: AppleScript and Safari clickable
link example


10.3: AppleScript and Safari clickable
link example
10/29/2003 12:32 PM
Just noticed this today while perusing the AppleScript area at Apple. I was looking for GUI Scripting to do download and install, but they seem to indicate that GUI Scripting is installed by default in Panther. One thing that...

Apple: Safari, AppleScript and
JavaScript


Apple: Safari, AppleScript and
JavaScript
10/29/2003 02:19 AM
As noted yesterday, the latest version of Safari includes the 'do JavaScript' command in its AppleScript dictionary. By using the command, users can create AppleScript scripts that interact with the Safari JavaScript DOM (Document Object Model). Apple provides sample scripts along with links to Safari Developer FAQ, Safari JavaScript DOM Part 1 and Safari JavaScript DOM Part 2.

An AppleScript to launch Safari and open
a given site


An AppleScript to launch Safari and open
a given site
07/23/2004 11:38 AM
I have been plagued with a bug, for some time and for many verisons of Safari, that for one reason or another insists on resetting my Home Page to the "factory default settings" every so often. Just often enough to be really ...

An improved 'Combine Windows'
AppleScript for Safari


An improved 'Combine Windows'
AppleScript for Safari
04/09/2004 03:59 PM
The "Combine Windows" Safari script (available on the Safari AppleScript page) takes all the open browser windows and consolidates them into one tabbed window. The following script gathers up all tabs in all browser windows and combines them into one window

Open new Safari window with an
AppleScript application


Open new Safari window with an
AppleScript application
12/10/2003 11:28 AM
The Safari dock icon behavior has always annoyed me. If you have no windows open and click on it, it will open a new Safari window. Great. However, if you have other windows open or minimized to the dock, it will just rest...

An AppleScript to email Safari URLs with
titles via Mail


An AppleScript to email Safari URLs with
titles via Mail
03/21/2003 10:17 AM
I've been trying to use Mail/Safari rather than Mozilla. One of the (many) things I miss is the ability to select "send link" when viewing a page, to have a new message created with the page title as the subject and the URL ...

AppleScript for removing performance
bottlenecks in Safari (deletes
potentially problematic .plist files)


AppleScript for removing performance
bottlenecks in Safari (deletes
potentially problematic .plist files)
06/22/2005 02:39 AM
MacFixIt readers John Boyden and Tom X have put together a small AppleScript that will delete the QuickTime .plist file in question, as well as a few other preference files that may cause issues with Safari from time to time.

Potential Security Flaw in Symantec
Gateway Security 360R


Potential Security Flaw in Symantec
Gateway Security 360R
06/09/2004 02:01 PM
Dev Null (Jun 08 2004)

RE: Potential Security Flaw in Symantec
Gateway Security 360R


RE: Potential Security Flaw in Symantec
Gateway Security 360R
06/11/2004 09:53 AM
Symantec Product Security Team (Jun 10 2004)

Other News: Safari JavaScript
Vulnerability


Other News: Safari JavaScript
Vulnerability
03/08/2004 11:09 PM
Insecure.ws reports a security vulnerability in Safari's JavaScript.

Apple patches vulnerability in Safari


Apple patches vulnerability in Safari 05/21/2004 06:53 PM

Apple patches vulnerability in Safari
(MacCentral)


Apple patches vulnerability in Safari
(MacCentral)
05/21/2004 07:05 PM
MacCentral - Apple Computer Inc. issued an update on Friday to fix a reported security hole in its Safari Web Browser. The venerability, which was classified as "Extremely Critical" by security firm Secunia, allowed the execution of malicious code on the users computer.

Safari, IE Vulnerability Allows
Executiion Of Malicious Code


Safari, IE Vulnerability Allows
Executiion Of Malicious Code
05/17/2004 06:08 PM
The vulnerability takes advantage of the "help" URI handler and "allows execution of arbitrary local scripts (.scpt) via the classic directory traversal character sequence using 'help:runscript.'" By Jim Dalrymple, MacCentral (via MyAppleMenu)

Safari, IE vulnerability allows
execution of malicious code


Safari, IE vulnerability allows
execution of malicious code
05/17/2004 04:22 PM
In what is being described as a "highly critical" vulnerability, security firm Secunia on Monday issued an advisory to all Mac OS X users that surf the Web with Microsoft's Internet Explorer or Apple's Safari Web browsers.

Safari, IE vulnerability allows
execution of malicious code (MacCentral)


Safari, IE vulnerability allows
execution of malicious code (MacCentral)
05/17/2004 04:23 PM
MacCentral - In what is being described as a "highly critical" vulnerability, security firm Secunia on Monday issued an advisory to all Mac OS X users that surf the Web with Microsoft's Internet Explorer or Apple's Safari Web browsers.

[SECURITY] [DSA 519-1] New CVS packages
fix several potential security problems


[SECURITY] [DSA 519-1] New CVS packages
fix several potential security problems
06/15/2004 06:24 PM
Martin Schulze (Jun 15 2004)

Input Validation Vulnerability in Apple
Safari version 1.2.4 v125.12


Input Validation Vulnerability in Apple
Safari version 1.2.4 v125.12
02/05/2005 09:38 PM
Jonathan Rockway (Feb 04 2005)

Re: Input Validation Vulnerability in
Apple Safari version 1.2.4 v125.12


Re: Input Validation Vulnerability in
Apple Safari version 1.2.4 v125.12
02/05/2005 09:38 PM
Nicolas Gregoire (Feb 05 2005)

[SECURITY] [DSA 504-1] New heimdal
packages fix potential buffer overflow


[SECURITY] [DSA 504-1] New heimdal
packages fix potential buffer overflow
05/18/2004 11:52 AM
Martin Schulze (May 18 2004)

[SECURITY] [DSA 245-1] New dhcp3
packages fix potential network flood


[SECURITY] [DSA 245-1] New dhcp3
packages fix potential network flood
01/01/2004 04:31 AM
Martin Schulze (Jan 28 2003)

[SECURITY] [DSA 552-1] New imlib2
packages fix potential arbitrary code
execution


[SECURITY] [DSA 552-1] New imlib2
packages fix potential arbitrary code
execution
09/22/2004 02:20 PM
Martin Schulze (Sep 22 2004)

Safari security advisory issued


Safari security advisory issued 05/17/2004 04:42 PM
Secunia has posted a security advisory for a "highly critical" vulnerability found in Apple's Safari Web browser that could potentially allow malicious Web sites to compromise a vulnerable system...

Security Update Offers Safari Cookies
Fix


Security Update Offers Safari Cookies
Fix
12/05/2003 07:51 PM
By Peter Cohen (MacCentral via MyAppleMenu)

Apple releases Safari security update


Apple releases Safari security update 12/05/2003 03:11 PM
Apple today released Security Update 2003-12-05, which updates Safari to prevent unauthorized access to a user's cookies...

Notes and Tips: Safari vs. Security
Update


Notes and Tips: Safari vs. Security
Update
04/04/2005 11:21 AM
Apple Discussions wrestle with link problems following Security Update 2005-003.

Security update offers Safari cookies
fix


Security update offers Safari cookies
fix
12/05/2003 03:12 PM
Apple on Friday released Security Update 2003-12-05. The new update is available for download through the Software Update system preferences pane.

[security bulletin] SSRT4782 rev. 0
HP-UX CIFS Server potential remote root
access


[security bulletin] SSRT4782 rev. 0
HP-UX CIFS Server potential remote root
access
07/27/2004 12:35 PM
Boren, Rich (SSRT) (Jul 27 2004)

[security bulletin] SSRT4785 rev. 0
HP-UX Process Resource Manager (PRM)
potential data corruption


[security bulletin] SSRT4785 rev. 0
HP-UX Process Resource Manager (PRM)
potential data corruption
08/10/2004 12:20 PM
Boren, Rich (SSRT) (Aug 10 2004)

[security bulletin] SSRT4717 rev.0 HP
Tru64 UNIX SSL/TLS Potential Remote
Denial of Service (DoS)


[security bulletin] SSRT4717 rev.0 HP
Tru64 UNIX SSL/TLS Potential Remote
Denial of Service (DoS)
06/15/2004 01:41 PM
Boren, Rich (SSRT) (Jun 14 2004)

[security bulletin] SSRT4782 rev. 1
HP-UX CIFS Server potential remote root
access


[security bulletin] SSRT4782 rev. 1
HP-UX CIFS Server potential remote root
access
08/06/2004 01:11 PM
Boren, Rich (SSRT) (Aug 06 2004)

[security bulletin] SSRT4741 rev.0 DCE
for HP Tru64 UNIX Potential RPC Buffer
Overrun Attack


[security bulletin] SSRT4741 rev.0 DCE
for HP Tru64 UNIX Potential RPC Buffer
Overrun Attack
06/25/2004 11:55 AM
Boren, Rich (SSRT) (Jun 24 2004)

[security bulletin] SSRTSSRT4778 Rev.0
Mozilla Application Suite for HP Tru64
UNIX libpng Potential Overflows


[security bulletin] SSRTSSRT4778 Rev.0
Mozilla Application Suite for HP Tru64
UNIX libpng Potential Overflows
08/06/2004 03:14 PM
Boren, Rich (SSRT) (Aug 05 2004)

[security bulletin] SSRT4741 rev.1 DCE
for HP OpenVMS Potential RPC Buffer
Overflow Attack VU#259796, VU#568148,
VU#326746


[security bulletin] SSRT4741 rev.1 DCE
for HP OpenVMS Potential RPC Buffer
Overflow Attack VU#259796, VU#568148,
VU#326746
07/14/2004 01:42 PM
Boren, Rich (SSRT) (Jul 14 2004)

Safari Magic 1.0 adds numerous tools to
Safari


Safari Magic 1.0 adds numerous tools to
Safari
07/20/2004 02:43 AM
Stephen Becker has announced the release of Safari Magic 1.0, a utility which adds several tools to Safari...

OS X security vulnerability


OS X security vulnerability 12/16/2003 06:33 PM
A new Mac OS X security vulnerability has been discovered. Apparantly this vulnerability can allow execution of arbitrary code with "root" priviledges. The issue is considered a "Less Critical" vulnerability, and affects Mac OS X 10.3.1 and possibly other versions of the operating system.

vBulletin Security Vulnerability


vBulletin Security Vulnerability 01/22/2004 02:58 AM
gcf_at_hush.com (Jan 20 2004)
Grok Description matches for Potential Safari/HelpViewer security vulnerability; AppleScript fix
GrokA matches for Potential Safari/HelpViewer security vulnerability; AppleScript fix

Use AppleScript to create drag and drop
icons for shell scripts


Use AppleScript to create drag and drop
icons for shell scripts
12/24/2003 01:20 PM
You can use AppleScript to create drag and drop icons for shell scripts or X11 applications. Here's how you would create a drag and drop icon for Emacs in Terminal.app:Launch Script Editor (Applications -> AppleScript -> Scr...

An AppleScript to remove Address Book
duplicates


An AppleScript to remove Address Book
duplicates
04/14/2005 09:46 AM
To get rid of duplicates in Address Book, I wrote the following AppleScript. Copy and paste it into Script Editor, and save it as a script. As Rob would say, "make sure you have a good backup." So from the file menu in Addres...

AppleScript application design tool
FaceSpan now at v4.2


AppleScript application design tool
FaceSpan now at v4.2
06/09/2004 03:47 PM
Developer Digital Technology International has released FaceSpan 4.2. The new version of its tool for designing and building AppleScript applications adds a terminology definitions pop-up in the Script Editor; "Show Superclass," "Back" and "Forward" buttons in the Dictionary Viewer toolbar; a text completion feature in the Script Editor; a bug fix; and more. This is a US$99 upgrade, while the full version, which includes an unlimited runtime license, is $199. A lite version, which features a single runtime license that limits compiled applications to running on the computer where FaceSpan is installed, is $89.

Make an AppleScript Studio application
self-update


Make an AppleScript Studio application
self-update
04/06/2005 09:26 AM
Here's a pair of handlers to include in an AppleScript Studio project to have an application update itself. The first handler creates a folder called "TempFolder" at the root of the startup disk, so we have a consistent space...

Apple developing AppleScript 1.10 for
Mac OS X 10.4 Tiger


Apple developing AppleScript 1.10 for
Mac OS X 10.4 Tiger
08/02/2004 08:57 PM
Apple Computer will include AppleScript 1.10 with Mac OS X version 10.4 "Tiger," AppleInsider has learned. The release will include many new features and enhancements while correcting numerous problems found with AppleScript 1.9.3 and earlier versions.

Apple offers iTunes Playlist to DVD
AppleScript


Apple offers iTunes Playlist to DVD
AppleScript
01/08/2004 07:17 PM
Apple has posted a "Playlist to DVD" AppleScript to its Web site for iDVD 4...

Add/Remove icon


Add/Remove icon 07/11/2004 01:43 PM

iChat Streaming Icon brings your buddy
icon to life


iChat Streaming Icon brings your buddy
icon to life
01/22/2004 01:00 PM
iChat Streaming Icon 1.2 is the latest version of the iChat AV enhancement that allows you to change your static buddy icon to an animation or a live video preview of yourself (requires iSight or other FireWire cam)...

An OS 9 / Classic fix for unmountable
FireWire drives


An OS 9 / Classic fix for unmountable
FireWire drives
08/27/2004 01:38 PM
I have had a ongoing problem with miscellaneous FireWire drives that won't mount. Clicking on the grayed-out drive in the Disk Utility only creates an endless beachball. After trying DiskWarrior, Data Rescue, and other variou...

Force-mount unmountable disk images


Force-mount unmountable disk images 09/15/2004 11:06 AM
On my machine, OS X 10.3.x seems to refuse to mount any disk image files (.DMG) after a few days of use, and DMG files which mounted just fine before now fail with a "No mountable file systems" error message. Most people ass...

AppleScript in Panther


AppleScript in Panther 10/29/2003 12:13 AM
Topping the list of important features is the new scriptable image processing architecture called Image Events. Script Editor application has been totally re-written to become a native Mac OS X application. Menus, windows, and dialogs of these applications can now be queried and controlled via AppleScript's new Graphic User Interface scripting architecture. iCal 1.5 includes the ability to set the execution of scripts as an action for calendar events.

AppleScript Documentation


AppleScript Documentation 10/29/2003 12:13 AM
AppleScript is Apple's native scripting technology. It enables users to directly control applications, including the Mac OS itself, by creating sets of English-like instructions, or scripts. Developers can make their applications scriptable; that is, capable of responding to Apple events. Carbon and Cocoa applications both support scripting, allowing applications to execute scripts or send individual Apple events to take advantage of features of other applications.

Applescript vs. Cocoa


Applescript vs. Cocoa 02/07/2005 01:20 AM
"Ken Ferry mailed me about my iTunes controller, wondering what the overhead was for using Applescript in my Lisp controller. With a little experimentation I found that calling out to the shell added about 350ms to the runtime for each call, plus execution time. To refresh a page which interrogates iTunes for the current track, the current volume, and whether it was set to play on random or not would take well over a second just to call the scripts."

macscripter's appleScript faq


macscripter's appleScript faq 12/02/2003 11:00 AM
MacScripter's AppleScript FAQ section has undergone a massive update. Julio J. Sancho (aka JJ) has re-organized the categories, updated the contents, and unified the FAQs overall appearance. Plus, JJ has added many important new AppleScript FAQs. MacScripter's AppleScript FAQ section is a comprehensive list of frequently asked questions based on a simple Q&A format. The FAQs are indexed and split into several sub-categories.

Top Ten AppleScript Tips


Top Ten AppleScript Tips 02/01/2005 09:35 PM

If you think of AppleScript as only a nerdy, workflow-automation tool, you're missing out on a lot of power. By Adam Goldstein, O'Reilly Network


Help With iTunes AppleScript


Help With iTunes AppleScript 01/22/2004 12:57 PM

AppleScript Editor 2.0


AppleScript Editor 2.0 11/03/2003 04:03 PM
Read, write, record, and save AppleScript scripts

What is "delegation" in AppleScript?


What is "delegation" in AppleScript? 06/17/2004 12:59 PM
Delegation in AppleScript is similar to a filter. Using delegation, you can catch events which are not owned by you, then make some operations or let them flow.

Constructors in AppleScript


Constructors in AppleScript 06/10/2004 01:12 PM
jj: "Sample code to create and use a special structure in AppleScript mostly unknown as 'constructor'... Some of the features defined in the "constructor" maybe available only to OS X or special email clients (?), but this is simple source-code and can be adaptated."

Experiences with AppleScript


Experiences with AppleScript 04/08/2005 12:25 PM
Simon Brown: "If you've not seen AppleScript, it's a cross between a 3rd generation language and english. There's a fairly good language guide on the Apple website, although it's no tutorial. The script editor itself works well and I particularly like the way it auto-indents when you save or compile."

AppleScript Basics


AppleScript Basics 08/12/2004 01:26 PM
You use AppleScript's Script Editor application to write small programs or scripts that include specially worded statements. AppleScript statements are converted by Mac OS into Apple events--messages that can be understood by the operating system and applications. When you run a script, the script can send instructions to the operating system or applications and receive messages in return.

Potential Safari/HelpViewer security vulnerability; AppleScript fix

The following phrases have been identified by the grok system as matching this entry: applescript amd copy file "drag icon" "tell application" fix apple unmountable dmg hdiutil aes 256 "













Also check out:


Grok

Ipod Porn on the
Rise

Brief Abstract of
Wikipedia's
Mesothelioma Cancer
page

Get first aid
instructions in your
cell phone

IE is crap
JSPWiki gains
podcasting support

washingtonpost.com:
'+title+'

Harry Potter Website
Gifted pupil summer
schools rated

Arms exports pledge
'worthless'

Man arrested over
Antrim killing

Man is arrested at
Windsor Castle

Olympics: London
awaits decision

Liverpool 'accept
Thai bid'

AlbumPlayer v3.3
QVCS-Pro v3.6 Build
28

Anarchists,
Libraries and
Freedom

Perl Snapshot Is Not
Incremental Backup
0.8

Munin 1.0.0pre5
(Stable)

Get 'em while
they're hot

EyeBlogging
Titanic firm
unlikely to own
artefacts (Reuters)

Blackpool wants to
mimic Las Vegas
(Reuters)

MySQL Adds High-end
Enterprise Features
to Database

Informal request for
assistance...

Export of U.S. Jobs
Seen Up - Report

AMD Could Boost
Earnings With A Jump
On Intel

AI Expert Newsletter
Web Hosting News:
Former Microsoft
Marketing Lead Joins
SWsoft; Kurt Daniel
to Drive Overall
Marketing; SWsoft

Rebound seen for ERP
software

Salesforce delays
IPO

Computer Sciences'
Earnings Up 17
Percent

Internet delays bug
bank clients

L.L. Bean Sues
Pop-Up Advertisers

SEC Fines Lucent
Technologies $25
Million

MDKSA-2004:044 -
Updated libuser
packages fix
vulnerability

MDKSA-2004:045 -
Updated passwd
packages fix
vulnerabilities

MDKSA-2004:046 -
Updated apache
packages fix a
number of
vulnerabilities

Mobile phone
operators still
waiting for the
third generation

Portable Bluetooth
Keyboard Will Hit
the Market Next
Month

Court Upholds
Application of
Disability Law in
Court Access

U.S. Rights Report
Is Released After
Delay

Venus Returns for
Its Shining Hour

When Alzheimer's
Steals the Mind, How
Aggressively to
Treat the Body?

Unnatural Weather,
Natural Disasters: A
New U.N. Focus

When Retirement
Leaves an Emptiness,
Some Fill It With
Alcohol

Unpopular in the
Animal Kingdom? Try
Borrowing Another
Cologne

SARS's Second Act,
Playing in
Laboratories

Pollution Alters DNA
in Mice, Study Finds

Creatures Stir, and
Once Again the
Universe Takes
Flight

Revival of an Old
Cure:
Bacteria-Eating
Viruses

From Ancient Greece
to Iraq, the Power
of Words in Wartime

A Dietary Mineral
You Need (and
Probably Didn't Know
It)

Frogs and Fish: Not
the Best of Friends

Hazards: How to Duck
Swimmer's Itch

Sic Transit Venus:
I'll Miss You, but
We'll Meet in 8
Years

what is grok?