Apple Safari WebKit 'alink' Property Memory Leak Remote Denial of Service Vulnerability
BID:33080
Info
Apple Safari WebKit 'alink' Property Memory Leak Remote Denial of Service Vulnerability
| Bugtraq ID: | 33080 |
| Class: | Design Error |
| CVE: |
CVE-2008-5821 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 01 2009 12:00AM |
| Updated: | Apr 13 2015 09:12PM |
| Credit: | Jeremy Brown |
| Vulnerable: |
Apple Safari 3.2 Apple Mobile Safari 0 |
| Not Vulnerable: | |
Discussion
Apple Safari WebKit 'alink' Property Memory Leak Remote Denial of Service Vulnerability
Apple Safari is prone to a denial-of-service vulnerability that resides in the WebKit library.
Remote attackers can exploit this issue to crash the affected browser, denial-of-service condition.
Apple Safari 3.2 running on Microsoft Windows Vista is vulnerable; other versions running on different platforms may also be affected.
Note (December 20, 2010): Safari on iOS 4.0.1 is also vulnerable.
Apple Safari is prone to a denial-of-service vulnerability that resides in the WebKit library.
Remote attackers can exploit this issue to crash the affected browser, denial-of-service condition.
Apple Safari 3.2 running on Microsoft Windows Vista is vulnerable; other versions running on different platforms may also be affected.
Note (December 20, 2010): Safari on iOS 4.0.1 is also vulnerable.
Exploit / POC
Apple Safari WebKit 'alink' Property Memory Leak Remote Denial of Service Vulnerability
The following exploit code is available:
The following exploit code is available:
Solution / Fix
Apple Safari WebKit 'alink' Property Memory Leak Remote Denial of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Apple Safari WebKit 'alink' Property Memory Leak Remote Denial of Service Vulnerability
References:
References:
- Safari (Webkit) version 3.2 remote memory leak exploit. (Jermey Brown)
- Safari Homepage (Apple)