Apple Safari Unspecified Remote Code Execution Variant Vulnerability
BID:34179
Info
Apple Safari Unspecified Remote Code Execution Variant Vulnerability
| Bugtraq ID: | 34179 |
| Class: | Unknown |
| CVE: |
CVE-2009-1060 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 19 2009 12:00AM |
| Updated: | Mar 30 2009 04:36PM |
| Credit: | Charlie Miller |
| Vulnerable: |
Apple Safari 3.2.2 for Windows Apple Safari 3.1.2 for Windows Apple Safari 3.1.2 Apple Safari 3.1.1 for Windows Apple Safari 3.1.1 Apple Safari 3.2 Apple Safari 3.1 for Windows Apple Safari 3.1 Apple Safari 3 |
| Not Vulnerable: | |
Discussion
Apple Safari Unspecified Remote Code Execution Variant Vulnerability
Apple Safari is prone to an unspecified remote code-execution vulnerability.
This issue was demonstrated at the CanSecWest 2009 conference. Technical details are not yet available; we will update this BID as more information emerges.
Attackers can exploit this issue to execute arbitrary code in the context of the user running the browser. Successful exploits will compromise the application and possibly the computer. Failed attacks will cause denial-of-service conditions.
Apple Safari is prone to an unspecified remote code-execution vulnerability.
This issue was demonstrated at the CanSecWest 2009 conference. Technical details are not yet available; we will update this BID as more information emerges.
Attackers can exploit this issue to execute arbitrary code in the context of the user running the browser. Successful exploits will compromise the application and possibly the computer. Failed attacks will cause denial-of-service conditions.
Exploit / POC
Apple Safari Unspecified Remote Code Execution Variant Vulnerability
This issue was demonstrated at the CanSecWest 2009 conference. This exploit is not otherwise publicly available or known to be circulating in the wild.
This issue was demonstrated at the CanSecWest 2009 conference. This exploit is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
Apple Safari Unspecified Remote Code Execution Variant Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Apple Safari Unspecified Remote Code Execution Variant Vulnerability
References:
References:
- Pwn2Own 2009 Day 1 - Safari, Internet Explorer, and Firefox Taken Down by Four Z (TippingPoint)
- Pwn2Own 2009: Safari, IE 8 and Firefox exploited (Heise Media)
- Safari Home Page (Apple)