First published: Fri Aug 19 2005(Updated: )
Safari in WebKit in Mac OS X 10.4 to 10.4.2 directly accesses URLs within PDF files without the normal security checks, which allows remote attackers to execute arbitrary code via links in a PDF file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Safari | ||
macOS Yosemite | =10.4.1 | |
macOS Yosemite | =10.4 | |
macOS Yosemite | =10.4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-2522 is considered critical due to its potential to allow remote code execution.
To fix CVE-2005-2522, you should update Safari and macOS to the latest versions that address this vulnerability.
CVE-2005-2522 affects Safari in macOS versions 10.4 to 10.4.2.
CVE-2005-2522 can be exploited through specially crafted PDF files that contain malicious links.
As a workaround for CVE-2005-2522, users should avoid opening PDF files from untrusted sources until a fix is applied.