Apple WebKit Invalid Type Conversion Remote Code Execution Vulnerability
BID:24597
Info
Apple WebKit Invalid Type Conversion Remote Code Execution Vulnerability
| Bugtraq ID: | 24597 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-2399 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 22 2007 12:00AM |
| Updated: | Aug 02 2007 12:05AM |
| Credit: | Rhys Kidd is credited with discovering this vulnerability. |
| Vulnerable: |
WebKit Open Source Project WebKit 0 Apple Safari 3.0.1 Beta for Windows Apple Safari 2.0.4 Apple Safari 2.0.3 Apple Safari 2.0.2 Apple Safari 2.0.1 Apple Safari 1.3.1 Apple Safari 1.3 Apple Safari 1.2.3 Apple Safari 1.2.2 Apple Safari 1.2.1 Apple Safari 1.2 Apple Safari 1.1 Apple Safari 1.0 Apple Safari 3 Beta for Windows Apple Safari 3 Beta Apple Mobile Safari 0 Apple iPhone 1 |
| Not Vulnerable: |
Apple Safari 3.0.2 Beta for Windows Apple iPhone 1.0.1 |
Discussion
Apple WebKit Invalid Type Conversion Remote Code Execution Vulnerability
Apple WebKit is prone to a remote code-execution vulnerability.
An attacker may exploit this issue by enticing victims into opening a maliciously crafted HTML document.
Successful exploits can allow attackers to execute arbitrary code in the context of an application using the framework (typically Safari) or to cause denial-of-service conditions.
Apple WebKit is prone to a remote code-execution vulnerability.
An attacker may exploit this issue by enticing victims into opening a maliciously crafted HTML document.
Successful exploits can allow attackers to execute arbitrary code in the context of an application using the framework (typically Safari) or to cause denial-of-service conditions.
Exploit / POC
Apple WebKit Invalid Type Conversion Remote Code Execution Vulnerability
An attacker may exploit this issue by enticing victims into viewing a maliciously crafted webpage.
An attacker may exploit this issue by enticing victims into viewing a maliciously crafted webpage.
Solution / Fix
Apple WebKit Invalid Type Conversion Remote Code Execution Vulnerability
Solution:
Apple has released an updated version of the software that addresses this issue. Please see the references for details.
Apple security advisory APPLE-SA-2007-07-31 iPhone v1.0.1 Update is available.
Note that the iPhone update is available only through iTunes; it will not be available through the Software Update application or the Apple Downloads site. The update is automatically detected and downloaded by iTunes -- the user will be asked to install the update when the iPhone is docked.
Apple Safari 3.0.1 Beta for Windows
Solution:
Apple has released an updated version of the software that addresses this issue. Please see the references for details.
Apple security advisory APPLE-SA-2007-07-31 iPhone v1.0.1 Update is available.
Note that the iPhone update is available only through iTunes; it will not be available through the Software Update application or the Apple Downloads site. The update is automatically detected and downloaded by iTunes -- the user will be asked to install the update when the iPhone is docked.
Apple Safari 3.0.1 Beta for Windows
-
Apple Safari302Beta.dmg
http://www.apple.com/safari/download/Safari302Beta.dmg -
Apple SafariSetup.exe
Safari 3 Beta Update 3.0.2 for Windows XP or Vista
http://www.apple.com/safari/download/SafariSetup.exe
References
Apple WebKit Invalid Type Conversion Remote Code Execution Vulnerability
References:
References: