Apple Safari Memory Corruption and Address Bar Spoofing Vulnerabilities
RISK: Medium Risk
Multiple vulnerabilities have been identified in Apple Safari for Windows, which could be exploited by remote attackers to spoof arbitrary web sites, cause a denial of service or compromise a vulnerable system.
1. Due to a memory corruption error when handling overly long filenames, which could be exploited by attackers to crash an affected browser or execute arbitrary code by tricking a user into clicking a specially crafted URL (e.g. to download a ZIP archive).
2. Due to an error when handling certain windows, which could be exploited by malicious web sites to conduct phishing attacks.
Impact
- Remote Code Execution
- Spoofing
System / Technologies affected
- Safari for Windows 3.x
Solutions
There is no patch available for this vulnerability currently.
Temporary Solution: Do not browse untrusted web sites.
Vulnerability Identifier
- No CVE information is available
Source
Related Link
Share with