Apple Safari for Windows Corefoundation.DLL Denial of Service Vulnerability
BID:24497
Info
Apple Safari for Windows Corefoundation.DLL Denial of Service Vulnerability
| Bugtraq ID: | 24497 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-3284 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 16 2007 12:00AM |
| Updated: | May 07 2015 05:37PM |
| Credit: | Lostmon is credited with discovering this vulnerability. |
| Vulnerable: |
Apple Safari 3.0.1 Beta for Windows |
| Not Vulnerable: |
Apple Safari 3.0.2 Beta for Windows |
Discussion
Apple Safari for Windows Corefoundation.DLL Denial of Service Vulnerability
Apple Safari for Windows is prone to a denial-of-service vulnerability because it fails to properly handle user-supplied input.
An attacker may exploit this issue by enticing victims into opening a maliciously crafted HTML document.
Successful exploits can allow attackers to crash the affected browser, resulting in denial-of-service conditions. Attackers may also be able to execute arbitrary code, but Symantec had not confirmed this.
Safari 3.0.1 public beta for Windows is reported vulnerable.
Apple Safari for Windows is prone to a denial-of-service vulnerability because it fails to properly handle user-supplied input.
An attacker may exploit this issue by enticing victims into opening a maliciously crafted HTML document.
Successful exploits can allow attackers to crash the affected browser, resulting in denial-of-service conditions. Attackers may also be able to execute arbitrary code, but Symantec had not confirmed this.
Safari 3.0.1 public beta for Windows is reported vulnerable.
Exploit / POC
Apple Safari for Windows Corefoundation.DLL Denial of Service Vulnerability
An attacker may exploit this issue by enticing victims into viewing a maliciously crafted webpage.
The following proof of concept is available:
An attacker may exploit this issue by enticing victims into viewing a maliciously crafted webpage.
The following proof of concept is available:
Solution / Fix
Apple Safari for Windows Corefoundation.DLL Denial of Service Vulnerability
Solution:
Reports indicate this issue has been addressed in Safari 3.0.2 for Windows. Contact the vendor for details on obtaining the appropriate updates.
Apple Safari 3.0.1 Beta for Windows
Solution:
Reports indicate this issue has been addressed in Safari 3.0.2 for Windows. Contact the vendor for details on obtaining the appropriate updates.
Apple Safari 3.0.1 Beta for Windows
-
Apple Safari302Beta.dmg
http://www.apple.com/safari/download/Safari302Beta.dmg
References
Apple Safari for Windows Corefoundation.DLL Denial of Service Vulnerability
References:
References:
- Safari 3.0.1 (552.12.2) for windows corefoundation.dll DoS (Lostmon)
- Safari Homepage (Apple)