CVE-2008-2309: Medium severity apple ios and macos vulnerability
Incomplete blacklist vulnerability in CoreTypes in Apple Mac OS X before 10.5.4 allows user-assisted remote attackers to execute arbitrary code via a (1) .xht or (2) .xhtm file, which does not trigger a "potentially unsafe" warning message in (a) the Download Validation feature in Mac OS X 10.4 or (b) the Quarantine feature in Mac OS X 10.5.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-2309?
CVE-2008-2309 is classified as a medium severity vulnerability.
How do I fix CVE-2008-2309?
To fix CVE-2008-2309, update your Mac OS X to version 10.5.4 or later, where the vulnerability is patched.
What systems are affected by CVE-2008-2309?
CVE-2008-2309 affects Apple Mac OS X versions before 10.5.4, specifically 10.4.x and some 10.5.x versions.
Can CVE-2008-2309 be exploited remotely?
Yes, CVE-2008-2309 can be exploited by remote attackers via specially crafted .xht or .xhtm files.
What type of vulnerability is CVE-2008-2309?
CVE-2008-2309 is an incomplete blacklist vulnerability that allows remote code execution.