Apple Safari Multiple Vulnerabilities
Last Update Date:
18 Dec 2013 12:04
Release Date:
18 Dec 2013
3952
Views
RISK: High Risk
TYPE: Clients - Browsers
A security issue and multiple vulnerabilities have been identified in Apple Safari, which can be exploited by malicious people to bypass certain security restrictions and compromise a user's system.
- An error related to origin tracking can be exploited to autofill a form in a subframe of domain different than the main domain.
- A use-after-free error exists within webkit.
- Unspecified errors within webkit can be exploited to corrupt memory.
Successful exploitation of vulnerabilities #2 through #3 may allow execution of arbitrary code.
Impact
- Remote Code Execution
- Security Restriction Bypass
System / Technologies affected
- Versions prior to 6.1.1 and 7.0.1
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Update to version 6.1.1. or 7.0.1.
Vulnerability Identifier
- CVE-2013-2909
- CVE-2013-5195
- CVE-2013-5196
- CVE-2013-5197
- CVE-2013-5198
- CVE-2013-5199
- CVE-2013-5225
- CVE-2013-5227
- CVE-2013-5228
Source
Related Link
Share with