LaunchServices in Apple OS X before 10.10.2 does not properly handle file-type metadata, which allows attackers to bypass the Gatekeeper protection mechanism via a crafted JAR archive.
http://lists.apple.com/archives/security-announce/2015/Jan/msg00003.html
http://packetstormsecurity.com/files/130147/OS-X-Gatekeeper-Bypass.html
http://seclists.org/fulldisclosure/2015/Jan/109
https://exchange.xforce.ibmcloud.com/vulnerabilities/100519
http://support.apple.com/HT204244