Apple Safari BMP and GIF Files Remote Denial of Service and Information Disclosure Vulnerability
BID:27947
Info
Apple Safari BMP and GIF Files Remote Denial of Service and Information Disclosure Vulnerability
| Bugtraq ID: | 27947 |
| Class: | Unknown |
| CVE: |
CVE-2008-0894 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 22 2008 12:00AM |
| Updated: | Feb 22 2008 06:43PM |
| Credit: | Gynvael Coldwind is credited with the discovery of this vulnerability. |
| Vulnerable: |
Apple Safari 3.0.4 Beta for Windows Apple Safari 3.0.3 Beta for Windows Apple Safari 3.0.3 Beta Apple Safari 3.0.2 Beta for Windows Apple Safari 3.0.2 Beta Apple Safari 3.0.1 Beta for Windows Apple Safari 3.0.1 Beta Apple Safari 2.0.4 Apple Safari 2.0.3 Apple Safari 2.0.2 Apple Safari 2.0.1 Apple Safari 1.3.1 Apple Safari 1.3 Apple Safari 1.2.3 Apple Safari 1.2.2 Apple Safari 1.2.1 Apple Safari 1.2 Apple Safari 1.1 Apple Safari 1.0 Apple Safari Beta 2 Apple Safari 3 Beta for Windows Apple Safari 3 Beta Apple Safari 3 Apple Mobile Safari 0 |
| Not Vulnerable: | |
Discussion
Apple Safari BMP and GIF Files Remote Denial of Service and Information Disclosure Vulnerability
Apple Safari is prone to a remote vulnerability that may lead to a denial-of-service condition or information disclosure. This issue occurs when the application tries to handle malformed image files.
An attacker can exploit this issue to crash the affected application, denying service to legitimate users. Attackers may also obtain potentially sensitive information that may aid in further attacks.
Very few details are currently available. We will update this BID as more information emerges.
This issue may be related to the one described in BID 27826 (Multiple Web Browser BMP Partial Palette Information Disclosure and Denial Of Service Vulnerability).
Apple Safari is prone to a remote vulnerability that may lead to a denial-of-service condition or information disclosure. This issue occurs when the application tries to handle malformed image files.
An attacker can exploit this issue to crash the affected application, denying service to legitimate users. Attackers may also obtain potentially sensitive information that may aid in further attacks.
Very few details are currently available. We will update this BID as more information emerges.
This issue may be related to the one described in BID 27826 (Multiple Web Browser BMP Partial Palette Information Disclosure and Denial Of Service Vulnerability).
Exploit / POC
Apple Safari BMP and GIF Files Remote Denial of Service and Information Disclosure Vulnerability
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Apple Safari BMP and GIF Files Remote Denial of Service and Information Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Apple Safari BMP and GIF Files Remote Denial of Service and Information Disclosure Vulnerability
References:
References:
- Bug 408076 (Mozilla)
- Safari Homepage (Apple)
- FireFox 2.0.0.11 and Opera 9.50 beta Remote Memory Information Leak, FireFox 2.0 ("Gynvael Coldwind"
)