Safari Multiple Vulnerabilities
RISK: Medium Risk
Multiple vulnerabilities have been identified in Apple Safari, which could be exploited by remote attackers to disclose sensitive information, cause a denial of service or execute arbitrary code.
1. An error in WebKit when handling URLs containing a colon character in the host name, which could be exploited to conduct cross-site scripting attacks.
2. Abuffer overflow error in WebKit when handling JavaScript regular expressions, which could be exploited by remote attackers to crash an affected browser or compromise a vulnerable system via a specially crafted web page.
Impact
- Denial of Service
- Remote Code Execution
- Information Disclosure
System / Technologies affected
- Apple Safari versions prior to 3.1.1
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
Upgrade to Safari version 3.1.1 :
http://www.apple.com/support/downloads/safari311.html
Vulnerability Identifier
Source
Related Link
Share with