Summary
The host is installed with Apple Safari web browser and is prone to multiple vulnerabilities.
Impact
Successful exploitation could allow attackers to opening a maliciously crafted files, which leads to an unexpected application termination or arbitrary code execution.
Impact Level: System/Application
Solution
Upgrade to Apple Safari version 5.1.1 or later,
For updates refer to http://www.apple.com/safari/download/
Insight
The flaws are due to
- A directory traversal issue existed in the handling of 'safari-extension://' URLs.
- A policy issue existed in the handling of 'file://' URLs.
- An uninitialized memory access issue existed in the handling of SSL certificates.
- Multiple memory corruption issues existed in WebKit.
- A cross origin issue existed in the handling of the beforeload event, 'window.open' method, 'document.documentURI' property and inactive DOM windows in webkit.
- A logic issue existed in the handling of cookies in Private Browsing mode.
Affected
Apple Safari versions prior to 5.1.1 on Windows
References
Updated on 2017-03-28
Severity
Classification
-
CVSS Base Score: 9.3
AV:N/AC:M/Au:N/C:C/I:C/A:C
Related Vulnerabilities
- Adobe Flash Player Buffer Overflow Vulnerability - Apr14 (Windows)
- Adobe Acrobat Multiple Vulnerabilities April-2012 (Mac OS X)
- Adobe Acrobat Multiple Unspecified Vulnerabilities -01 May13 (Mac OS X)
- Adobe Air Multiple Vulnerabilities -01 May 13 (Windows)
- Adobe AIR Multiple Vulnerabilities-01 Jan15 (Mac OS X)