Apple Safari 3.1.1 For Windows Multiple Denial of Service and Spoofing Vulnerabilities
BID:28891
Info
Apple Safari 3.1.1 For Windows Multiple Denial of Service and Spoofing Vulnerabilities
| Bugtraq ID: | 28891 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 22 2008 12:00AM |
| Updated: | Apr 22 2008 10:27PM |
| Credit: | Juan Pablo Lopez Yacubian |
| Vulnerable: |
Apple Safari 3.1.1 |
| Not Vulnerable: | |
Discussion
Apple Safari 3.1.1 For Windows Multiple Denial of Service and Spoofing Vulnerabilities
Apple Safari is prone to multiple remote vulnerabilities, including:
- A denial-of-service vulnerability caused by a write-access violation.
- A denial-of-service vulnerability caused by a read-access violation.
- A vulnerability that allows attackers to spoof the content contained in the address bar.
An attacker can exploit these issues to crash the affected application or cause the victim to interact with the attacker's malicious site.
This issue affects Apple Safari 3.1.1 for Windows; other versions may also be affected.
Apple Safari is prone to multiple remote vulnerabilities, including:
- A denial-of-service vulnerability caused by a write-access violation.
- A denial-of-service vulnerability caused by a read-access violation.
- A vulnerability that allows attackers to spoof the content contained in the address bar.
An attacker can exploit these issues to crash the affected application or cause the victim to interact with the attacker's malicious site.
This issue affects Apple Safari 3.1.1 for Windows; other versions may also be affected.
Exploit / POC
Apple Safari 3.1.1 For Windows Multiple Denial of Service and Spoofing Vulnerabilities
Proofs of concept are available at this location:
http://es.geocities.com/jplopezy/pruebasafari3.html
Proofs of concept are available at this location:
http://es.geocities.com/jplopezy/pruebasafari3.html
Solution / Fix
Apple Safari 3.1.1 For Windows Multiple Denial of Service and Spoofing Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Apple Safari 3.1.1 For Windows Multiple Denial of Service and Spoofing Vulnerabilities
References:
References: