Impact:
A maliciously modified Keynote presentation could
be constructed to retrieve files from the local system.
Description:
With a specially crafted Keynote presentation and the
use of the "keynote:" URI handler, it is possible that
local files could be read and then sent to an arbitrary
network location. This issue has been addressed in two
ways: References to external resources have been limited,
and the registration of the "keynote:" URI handler has been
removed. This issue does not affect Keynote versions prior to
Keynote 2.
Credit to David Remahl (
www.remahl.se/david) for reporting this issue.