WebKit WBR Tags Use-After-Free Remote Code Execution Vulnerability
BID:46822
Info
WebKit WBR Tags Use-After-Free Remote Code Execution Vulnerability
| Bugtraq ID: | 46822 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2011-1344 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 09 2011 12:00AM |
| Updated: | Apr 18 2011 09:34PM |
| Credit: | VUPEN |
| Vulnerable: |
WebKit Open Source Project WebKit 1.2.5 WebKit Open Source Project WebKit 1.2.3 WebKit Open Source Project WebKit 1.2.2 WebKit Open Source Project WebKit r77705 WebKit Open Source Project WebKit r52833 WebKit Open Source Project WebKit r52401 WebKit Open Source Project WebKit r51295 WebKit Open Source Project WebKit r38566 WebKit Open Source Project WebKit 1.2.X WebKit Open Source Project WebKit 1.2.2-1 WebKit Open Source Project WebKit 0 Apple Safari 4.1.2 for Windows Apple Safari 4.0.5 for Windows Apple Safari 4.0.5 Apple Safari 4.0.4 for Windows Apple Safari 4.0.4 Apple Safari 4.0.3 for Windows Apple Safari 4.0.3 Apple Safari 4.0.2 for Windows Apple Safari 4.0.2 Apple Safari 4.0.1 Apple Safari 5.0.4 for Windows Apple Safari 5.0.4 Apple Safari 5.0.3 for Windows Apple Safari 5.0.3 Apple Safari 5.0.2 for Windows Apple Safari 5.0.2 Apple Safari 5.0.1 for Windows Apple Safari 5.0.1 Apple Safari 5.0 for Windows Apple Safari 5.0 Apple Safari 4.1.3 for Windows Apple Safari 4.1.3 Apple Safari 4.1.2 Apple Safari 4.1.1 Apple Safari 4.1 Apple Safari 4.0 Beta Apple Safari 4.0 Apple Safari 4 for Windows Apple Safari 4 Beta Apple Safari 4 Apple Safari 0 Apple iTunes 10.2 Apple iTunes 10.1 Apple iTunes 10 Apple iPod Touch 0 Apple iPhone 0 Apple iPad 0 Apple iOS 4.2.1 Apple iOS 4.0.2 Apple iOS 4.0.1 Apple iOS 3.2.2 Apple iOS 3.2.1 Apple iOS 4.3.1 Apple iOS 4.3 Apple iOS 4.2.6 Apple iOS 4.2.5 Apple iOS 4.2 beta Apple iOS 4.2 Apple iOS 4.1 Apple iOS 4 Apple iOS 3.2 Apple iOS 3.0 |
| Not Vulnerable: |
Apple Safari 5.0.5 for Windows Apple Safari 5.0.5 Apple iTunes 10.2.2 Apple iOS 4.3.2 Apple iOS 4.2.7 |
Discussion
WebKit WBR Tags Use-After-Free Remote Code Execution Vulnerability
WebKit is prone to a remote code-execution vulnerability.
Attackers can exploit this issue by enticing an unsuspecting user into visiting a malicious webpage.
Successful attacks will allow attackers to execute arbitrary code within the context of the application. Failed exploit attempts will result in a denial-of-service condition.
WebKit is prone to a remote code-execution vulnerability.
Attackers can exploit this issue by enticing an unsuspecting user into visiting a malicious webpage.
Successful attacks will allow attackers to execute arbitrary code within the context of the application. Failed exploit attempts will result in a denial-of-service condition.
Exploit / POC
WebKit WBR Tags Use-After-Free Remote Code Execution Vulnerability
A working commercial exploit is available through VUPEN Security - Exploit and PoCs Service. This exploit is not otherwise publicly available or known to be circulating in the wild.
NOTE: To exploit this issue through iTunes, an attacker must first execute a successful man-in-the-middle attack.
A working commercial exploit is available through VUPEN Security - Exploit and PoCs Service. This exploit is not otherwise publicly available or known to be circulating in the wild.
NOTE: To exploit this issue through iTunes, an attacker must first execute a successful man-in-the-middle attack.
Solution / Fix
WebKit WBR Tags Use-After-Free Remote Code Execution Vulnerability
Solution:
Updates are available. Please see the references for more information.
Apple Safari 5.0.4
Apple Safari 5.0.4 for Windows
Solution:
Updates are available. Please see the references for more information.
Apple Safari 5.0.4
-
Apple Safari5.0.5SnowLeopard.dmg
Safari for Mac OS X v10.6.5 and later
http://www.apple.com/safari/download/ -
Apple Safari5.0.5Leopard.dmg
Safari for Mac OS X v10.5.8
http://www.apple.com/safari/download/
Apple Safari 5.0.4 for Windows
-
Apple APPLE-SA-2011-04-14-3 Safari_Setup.exe
Safari for Windows 7, Vista or XP from the Microsoft Choice Screen
http://www.apple.com/safari/download/ -
Apple APPLE-SA-2011-04-14-3 SafariQuickTimeSetup.exe
Safari+QuickTime for Windows 7, Vista or XP
http://www.apple.com/safari/download/ -
Apple APPLE-SA-2011-04-14-3 SafariSetup.exe
Safari for Windows 7, Vista or XP
http://www.apple.com/safari/download/
References
WebKit WBR Tags Use-After-Free Remote Code Execution Vulnerability
References:
References:
- Apple Safari Homepage (Apple)
- Day One At Pwn2Own Takes Out Microsoft Internet Explorer and Apple Safari (darknet)
- Safari/MacBook first to fall at Pwn2Own 2011 (Ryan Naraine)
- VUPEN Security Research - Apple Safari Text Nodes Remote Use-after-free Vulnerab ("VUPEN Security Research"
) - ZDI-11-135: (Pwn2Own) WebKit WBR Tag Removal Remote Code Execution Vulnerabilit (ZDI Disclosures
) - APPLE-SA-2011-04-18-1 iTunes 10.2.2 (Apple)
- ZDI-11-135 (Pwn2Own) WebKit WBR Tag Removal Remote Code Execution Vulnerability (Zero Day Initiative)