Apple Safari File Download Remote Denial of Service Vulnerability
BID:28404
Info
Apple Safari File Download Remote Denial of Service Vulnerability
| Bugtraq ID: | 28404 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 22 2008 12:00AM |
| Updated: | Mar 24 2008 10:30PM |
| Credit: | Juan Pablo Lopez Yacubian |
| Vulnerable: |
Apple Safari 3.1 |
| Not Vulnerable: | |
Discussion
Apple Safari File Download Remote Denial of Service Vulnerability
Apple Safari is prone to a remote denial-of-service vulnerability.
An attacker can exploit this issue to crash the affected application, denying service to legitimate users. Arbitrary code execution may be possible, but this has not been confirmed.
This issue affects Safari 3.1 running on Microsoft Windows.
Apple Safari is prone to a remote denial-of-service vulnerability.
An attacker can exploit this issue to crash the affected application, denying service to legitimate users. Arbitrary code execution may be possible, but this has not been confirmed.
This issue affects Safari 3.1 running on Microsoft Windows.
Exploit / POC
Apple Safari File Download Remote Denial of Service Vulnerability
A web page demonstrating this vulnerability is available at the following URI:
http://es.geocities.com/jplopezy/pruebasafari2.html
A web page demonstrating this vulnerability is available at the following URI:
http://es.geocities.com/jplopezy/pruebasafari2.html
Solution / Fix
Apple Safari File Download Remote Denial of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Apple Safari File Download Remote Denial of Service Vulnerability
References:
References: