WebKit CVE-2011-0160 Unspecified Memory Corruption Vulnerability
BID:46808
Info
WebKit CVE-2011-0160 Unspecified Memory Corruption Vulnerability
| Bugtraq ID: | 46808 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 09 2011 12:00AM |
| Updated: | Mar 09 2011 12:00AM |
| Credit: | McIntosh Cooey of Twelve Hundred Group, Harald Hanche-Olsen, Chuck Hohn of 1111 Internet LLC working with CERT, and Paul Hinze of Braintree. |
| Vulnerable: |
WebKit Open Source Project WebKit 1.2.5 WebKit Open Source Project WebKit 1.2.3 WebKit Open Source Project WebKit 1.2.2 WebKit Open Source Project WebKit r77705 WebKit Open Source Project WebKit r52833 WebKit Open Source Project WebKit r52401 WebKit Open Source Project WebKit r51295 WebKit Open Source Project WebKit r38566 WebKit Open Source Project WebKit 1.2.X WebKit Open Source Project WebKit 1.2.2-1 WebKit Open Source Project WebKit 0 Apple Safari 5.0.3 for Windows Apple Safari 5.0.3 Apple Safari 5.0.2 for Windows Apple Safari 5.0.2 Apple Safari 5.0.1 for Windows Apple Safari 5.0.1 Apple Safari 5.0 for Windows Apple Safari 5.0 Apple iOS 4.2.1 Apple iOS 4.0.2 Apple iOS 4.0.1 Apple iOS 3.2.2 Apple iOS 3.2.1 Apple iOS 4.2 beta Apple iOS 4.2 Apple iOS 4.1 Apple iOS 4 |
| Not Vulnerable: |
Apple Safari 5.0.4 for Windows Apple Safari 5.0.4 Apple iOS 4.3 |
Discussion
WebKit CVE-2011-0160 Unspecified Memory Corruption Vulnerability
WebKit is prone to an unspecified memory-corruption vulnerability.
An attacker can exploit this issue by enticing an unsuspecting user into visiting a malicious webpage with a vulnerable application.
Very few technical details are currently available. We will update this BID when more information emerges.
Successful exploits will allow attackers to execute arbitrary code in the context of the affected browser or cause denial-of-service conditions; other attacks may also be possible.
WebKit is prone to an unspecified memory-corruption vulnerability.
An attacker can exploit this issue by enticing an unsuspecting user into visiting a malicious webpage with a vulnerable application.
Very few technical details are currently available. We will update this BID when more information emerges.
Successful exploits will allow attackers to execute arbitrary code in the context of the affected browser or cause denial-of-service conditions; other attacks may also be possible.
Exploit / POC
WebKit CVE-2011-0160 Unspecified Memory Corruption Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
WebKit CVE-2011-0160 Unspecified Memory Corruption Vulnerability
Solution:
Apple has released updates to address this issue. Please see the references for more information.
Apple Safari 5.0.3
Apple Safari 5.0.3 for Windows
Solution:
Apple has released updates to address this issue. Please see the references for more information.
Apple Safari 5.0.3
-
Apple Safari5.0.4Leopard.dmg
Safari for Mac OS X v10.5.8
http://www.apple.com/safari/download/ -
Apple Safari5.0.4SnowLeopard.dmg
Safari for Mac OS X v10.6.5 and later
http://www.apple.com/safari/download/
Apple Safari 5.0.3 for Windows
-
Apple APPLE-SA-2011-03-09-2 SafariQuickTimeSetup.exe
Safari+QuickTime for Windows 7, Vista or XP
http://www.apple.com/safari/download/ -
Apple APPLE-SA-2011-03-09-2 Safari_Setup.exe
Safari for Windows 7, Vista or XP from the Microsoft Choice Screen
http://www.apple.com/safari/download/ -
Apple APPLE-SA-2011-03-09-2 SafariSetup.exe
Safari for Windows 7, Vista or XP
http://www.apple.com/safari/download/
References
WebKit CVE-2011-0160 Unspecified Memory Corruption Vulnerability
References:
References:
- iTunes Homepage (Apple)
- Webkit Homepage (Webkit)