WebKit 'Attr.style' Accessor Cross Domain Script Injection Vulnerability
BID:46814
Info
WebKit 'Attr.style' Accessor Cross Domain Script Injection Vulnerability
| Bugtraq ID: | 46814 |
| Class: | Input Validation Error |
| CVE: |
CVE-2011-0161 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 09 2011 12:00AM |
| Updated: | Mar 19 2015 08:12AM |
| Credit: | Apple |
| Vulnerable: |
WebKit Open Source Project WebKit 1.2.5 WebKit Open Source Project WebKit 1.2.3 WebKit Open Source Project WebKit 1.2.2 WebKit Open Source Project WebKit r77705 WebKit Open Source Project WebKit r52833 WebKit Open Source Project WebKit r52401 WebKit Open Source Project WebKit r51295 WebKit Open Source Project WebKit r38566 WebKit Open Source Project WebKit 1.2.X WebKit Open Source Project WebKit 1.2.2-1 WebKit Open Source Project WebKit 0 Apple Safari 5.0.3 for Windows Apple Safari 5.0.3 Apple Safari 5.0.2 for Windows Apple Safari 5.0.2 Apple Safari 5.0.1 for Windows Apple Safari 5.0.1 Apple Safari 5.0 for Windows Apple Safari 5.0 Apple Mobile Safari 0 Apple iPod Touch 0 Apple iPhone 0 Apple iPad 0 Apple iOS 4.2.1 Apple iOS 4.0.2 Apple iOS 4.0.1 Apple iOS 3.2.2 Apple iOS 3.2.1 Apple iOS 4.2 beta Apple iOS 4.2 Apple iOS 4.1 Apple iOS 4 Apple iOS 3.2 |
| Not Vulnerable: |
Apple Safari 5.0.4 for Windows Apple Safari 5.0.4 Apple iOS 4.3 |
Discussion
WebKit 'Attr.style' Accessor Cross Domain Script Injection Vulnerability
WebKit is prone to a cross-domain script-injection vulnerability.
Successful exploits will allow attackers to execute arbitrary script code within the context of the affected application.
WebKit is prone to a cross-domain script-injection vulnerability.
Successful exploits will allow attackers to execute arbitrary script code within the context of the affected application.
Exploit / POC
WebKit 'Attr.style' Accessor Cross Domain Script Injection Vulnerability
To exploit this issue, an attacker must entice an unsuspecting victim into visiting a malicious webpage.
To exploit this issue, an attacker must entice an unsuspecting victim into visiting a malicious webpage.
Solution / Fix
WebKit 'Attr.style' Accessor Cross Domain Script Injection Vulnerability
Solution:
Updates are available. Please see the references for details.
Apple Safari 5.0.3
Apple Safari 5.0.3 for Windows
Solution:
Updates are available. Please see the references for details.
Apple Safari 5.0.3
-
Apple Safari5.0.4Leopard.dmg
Safari for Mac OS X v10.5.8
http://www.apple.com/safari/download/ -
Apple Safari5.0.4SnowLeopard.dmg
Safari for Mac OS X v10.6.5 and later
http://www.apple.com/safari/download/
Apple Safari 5.0.3 for Windows
-
Apple APPLE-SA-2011-03-09-2 Safari_Setup.exe
Safari for Windows 7, Vista or XP from the Microsoft Choice Screen
http://www.apple.com/safari/download/ -
Apple APPLE-SA-2011-03-09-2 SafariQuickTimeSetup.exe
Safari+QuickTime for Windows 7, Vista or XP
http://www.apple.com/safari/download/ -
Apple APPLE-SA-2011-03-09-2 SafariSetup.exe
Safari for Windows 7, Vista or XP
http://www.apple.com/safari/download/
References
WebKit 'Attr.style' Accessor Cross Domain Script Injection Vulnerability
References:
References: