Apple Safari Automatic File Launch Remote Code Execution Vulnerability
BID:29835
Info
Apple Safari Automatic File Launch Remote Code Execution Vulnerability
| Bugtraq ID: | 29835 |
| Class: | Design Error |
| CVE: |
CVE-2008-2306 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 19 2008 12:00AM |
| Updated: | Apr 29 2009 10:16PM |
| Credit: | Will Dormann of CERT/CC |
| Vulnerable: |
Apple Safari 3.1.1 for Windows Apple Safari 3.0.4 Beta for Windows Apple Safari 3.0.3 Beta for Windows Apple Safari 3.0.2 Beta for Windows Apple Safari 3.0.1 Beta for Windows Apple Safari 3.1 for Windows Apple Safari 3 Beta for Windows |
| Not Vulnerable: |
Apple Safari 3.1.2 for Windows |
Discussion
Apple Safari Automatic File Launch Remote Code Execution Vulnerability
Apple Safari is prone to a remote code-execution vulnerability.
An attacker can exploit this issue by enticing an unsuspecting victim to visit a malicious webpage contained in a trusted Internet Explorer 7 zone or in an Internet Explorer 6 'local intranet' or 'Trusted site' zone.
Successfully exploiting this issue will allow attackers to run arbitrary code with the privileges of the user running the affected application.
This issue affects versions prior to Apple Safari 3.1.2 running on Microsoft Windows XP and Windows Vista.
Apple Safari is prone to a remote code-execution vulnerability.
An attacker can exploit this issue by enticing an unsuspecting victim to visit a malicious webpage contained in a trusted Internet Explorer 7 zone or in an Internet Explorer 6 'local intranet' or 'Trusted site' zone.
Successfully exploiting this issue will allow attackers to run arbitrary code with the privileges of the user running the affected application.
This issue affects versions prior to Apple Safari 3.1.2 running on Microsoft Windows XP and Windows Vista.
Exploit / POC
Apple Safari Automatic File Launch Remote Code Execution Vulnerability
An attacker can exploit this issue by enticing an unsuspecting victim to visit a malicious webpage.
An attacker can exploit this issue by enticing an unsuspecting victim to visit a malicious webpage.
Solution / Fix
Apple Safari Automatic File Launch Remote Code Execution Vulnerability
Solution:
The vendor released Safari 3.1.2 to address this issue. Please see the references for more information.
Apple Safari 3.1 for Windows
Apple Safari 3.1.1 for Windows
Solution:
The vendor released Safari 3.1.2 to address this issue. Please see the references for more information.
Apple Safari 3.1 for Windows
-
Apple Safari 3.1.2 - SafariQuickTimeSetup.exe
Safari+QuickTime for Windows XP or Vista
http://www.apple.com/safari/download/ -
Apple Safari 3.1.2 - SafariSetup.exe
http://www.apple.com/safari/download/
Apple Safari 3.1.1 for Windows
-
Apple Safari 3.1.2 - SafariQuickTimeSetup.exe
Safari+QuickTime for Windows XP or Vista
http://www.apple.com/safari/download/ -
Apple Safari 3.1.2 - SafariSetup.exe
http://www.apple.com/safari/download/
References
Apple Safari Automatic File Launch Remote Code Execution Vulnerability
References:
References: