Title: Downloaded Applications Can Execute on Mac IE 5.1 for
OS X
Date: 23 October 2001
Software: Internet Explorer 5.1 for Macintosh (r)
Impact: Run code of attacker's choice
Bulletin: MS01-053
Microsoft encourages customers to review the Security Bulletin at:
http://www.microsoft.com/technet/security/bulletin/MS01-053.asp.
The Macintosh OS X Operating System provides built-in support for
both BinHex and MacBinary file types. These file types allow for the
efficient transfer of information across networks by allowing
information to be compressed by the sender and then decompressed by
the recipient. This capability is particularly useful on the
Internet, by allowing users to dowload compressed files.
A vulnerability results because of a flaw in the way Mac OS X and Mac
IE 5.1 interoperate when BinHex and MacBinary file types are
downloaded. As a result, an application that is downloaded in either
of these formats can execute automatically once the download is
complete.
A user would first have to choose to download a file and allow the
download to fully complete before the application could execute.
Also, users can choose to disable the automatic decoding of both
these file types.
THE INFORMATION PROVIDED IN THE MICROSOFT KNOWLEDGE BASE IS
PROVIDED "AS IS" WITHOUT WARRANTY OF ANY KIND. MICROSOFT DISCLAIMS
ALL WARRANTIES, EITHER EXPRESS OR IMPLIED, INCLUDING THE
WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE.
IN NO EVENT SHALL MICROSOFT CORPORATION OR ITS SUPPLIERS BE LIABLE
FOR ANY DAMAGES WHATSOEVER INCLUDING DIRECT, INDIRECT, INCIDENTAL,
CONSEQUENTIAL, LOSS OF BUSINESS PROFITS OR SPECIAL DAMAGES, EVEN IF
MICROSOFT CORPORATION OR ITS SUPPLIERS HAVE BEEN ADVISED OF THE
POSSIBILITY OF SUCH DAMAGES. SOME STATES DO NOT ALLOW THE EXCLUSION
OR LIMITATION OF LIABILITY FOR CONSEQUENTIAL OR INCIDENTAL DAMAGES SO
THE FOREGOING LIMITATION MAY NOT APPLY.