Apple Safari CSS Denial of Service Vulnerability
BID:37039
Info
Apple Safari CSS Denial of Service Vulnerability
| Bugtraq ID: | 37039 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2009-4186 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 16 2009 12:00AM |
| Updated: | Apr 13 2015 09:06PM |
| Credit: | Jeremy Brown |
| Vulnerable: |
Apple Safari 4.0.3 for Windows |
| Not Vulnerable: | |
Discussion
Apple Safari CSS Denial of Service Vulnerability
Apple Safari is prone to a denial-of-service vulnerability because it fails to handle exceptional conditions.
An attacker can exploit this issue to crash the affected application, denying service to legitimate users.
Safari 4.0.3 for Windows is vulnerable; other versions may also be affected.
Apple Safari is prone to a denial-of-service vulnerability because it fails to handle exceptional conditions.
An attacker can exploit this issue to crash the affected application, denying service to legitimate users.
Safari 4.0.3 for Windows is vulnerable; other versions may also be affected.
Exploit / POC
Apple Safari CSS Denial of Service Vulnerability
To exploit this issue, an attacker must entice an unsuspecting victim into viewing a malicious webpage.
The following exploit code is available:
To exploit this issue, an attacker must entice an unsuspecting victim into viewing a malicious webpage.
The following exploit code is available:
Solution / Fix
Apple Safari CSS Denial of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].