Apple WebCore Framework XMLHttpRequests Remote Code Execution Vulnerability
BID:13202
Info
Apple WebCore Framework XMLHttpRequests Remote Code Execution Vulnerability
| Bugtraq ID: | 13202 |
| Class: | Access Validation Error |
| CVE: |
CVE-2005-0976 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 16 2005 12:00AM |
| Updated: | Jul 12 2009 12:56PM |
| Credit: | David Remahl <[email protected]> is credited with the discovery of this issue. |
| Vulnerable: |
Omni Group OmniWeb 5.1 Apple Safari RSS 2.0 pre-release Apple Safari 1.2.3 Apple Safari 1.2.2 Apple Safari 1.2.1 Apple Safari 1.2 Apple Safari 1.1 Apple Safari 1.0 |
| Not Vulnerable: |
Apple Safari 1.3 |
Discussion
Apple WebCore Framework XMLHttpRequests Remote Code Execution Vulnerability
A remote code execution vulnerability affects Apple's WebCore Framework. This issue is due to a failure of the affected framework library to securely handle remote scripts.
An attacker may leverage this issue to execute arbitrary code with the privileges of a user that activated the malicious remote script, facilitating unauthorized access and privilege escalation.
A remote code execution vulnerability affects Apple's WebCore Framework. This issue is due to a failure of the affected framework library to securely handle remote scripts.
An attacker may leverage this issue to execute arbitrary code with the privileges of a user that activated the malicious remote script, facilitating unauthorized access and privilege escalation.
Exploit / POC
Apple WebCore Framework XMLHttpRequests Remote Code Execution Vulnerability
A proof of concept has been provided and can be accessed at the following URI. It should be noted that this proof of concept has not been verified by Symantec.
http://remahl.se/david/vuln/001/demo.html
A proof of concept has been provided and can be accessed at the following URI. It should be noted that this proof of concept has not been verified by Symantec.
http://remahl.se/david/vuln/001/demo.html
Solution / Fix
Apple WebCore Framework XMLHttpRequests Remote Code Execution Vulnerability
Solution:
Apple has released security advisory APPLE-SA-2005-04-15 along with fixes dealing with this issue. Please see the referenced advisory for more information.
Apple Safari 1.0
Apple Safari 1.1
Apple Safari 1.2
Apple Safari 1.2.1
Apple Safari 1.2.2
Apple Safari 1.2.3
Solution:
Apple has released security advisory APPLE-SA-2005-04-15 along with fixes dealing with this issue. Please see the referenced advisory for more information.
Apple Safari 1.0
-
Apple Safari 1.3
http://www.apple.com/safari/download/
Apple Safari 1.1
-
Apple Safari 1.3
http://www.apple.com/safari/download/
Apple Safari 1.2
-
Apple Safari 1.3
http://www.apple.com/safari/download/
Apple Safari 1.2.1
-
Apple Safari 1.3
http://www.apple.com/safari/download/
Apple Safari 1.2.2
-
Apple Safari 1.3
http://www.apple.com/safari/download/
Apple Safari 1.2.3
-
Apple Safari 1.3
http://www.apple.com/safari/download/
References
Apple WebCore Framework XMLHttpRequests Remote Code Execution Vulnerability
References:
References:
- Apple WebCore Home Page (Apple)
- Mac OS X Homepage (Apple)
- OmniWeb Product Page (Omni Group)
- Safari Homepage (Apple)
- Shiira Project Web Browser Home Page (Shiira Project)
- AppleWebKit XMLHttpRequest arbitrary file disclosure vulnerability (David Remahl
)